A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
914 vulnerabilities with CWE-266
CVE-2025-69292
HIGH
WP Membership <1.6.5 - Privilege Escalation
CVSS 8.8
CVE-2025-69183
HIGH
Hospital Doctor Directory <1.3.9 - Privilege Escalation
CVSS 8.8
CVE-2025-69182
HIGH
e-plugins Institutions Directory <= 1.3.4 - Privilege Escalation
CVSS 8.8
CVE-2025-68869
CRITICAL
LazyTasks <1.4.01 - Privilege Escalation
CVSS 9.8
CVE-2025-68027
HIGH
Themefic Hydra Booking <1.1.32 - Privilege Escalation
CVSS 7.3
CVE-2025-67966
HIGH
Lawyer Directory <1.3.4 - Privilege Escalation
CVSS 8.8
CVE-2025-67953
HIGH
Booking Activities <1.16.44 - Privilege Escalation
CVSS 8.1
CVE-2025-50007
HIGH
Jthemes xSmart <= 1.2.9.4 - Privilege Escalation
CVSS 8.8
CVE-2025-67279
MEDIUM
TIM BPM Suite & TIM FLOW < 9.1.2 - Privilege Escalation via MD5 Password Hash Storage
CVSS 5.3
CVE-2025-67278
MEDIUM
TIM BPM Suite & TIM FLOW < 9.1.2 - Privilege Escalation via Crafted HTTP Request
CVSS 6.5
CVE-2025-31643
HIGH
WPCHURCH <2.7.0 - Privilege Escalation
CVSS 8.8
CVE-2025-29004
HIGH
AA-Team Premium Age Verification/Restriction <3.0.2 - Privilege Esc...
CVSS 8.8
CVE-2025-15213
MEDIUM
Student File Management System 1.0 - Improper Authorization via File Download Handler
CVSS 4.3
CVE-2025-15126
LOW
JeecgBoot < 3.9.0 - Improper Authorization via PositionId Argument in getPositionUserList
CVSS 3.1
CVE-2025-15125
LOW
JeecgBoot < 3.9.0 - Improper Authorization via departId Parameter in queryDepartPermission
CVSS 3.1
CVE-2025-15124
LOW
JeecgBoot < 3.9.0 - Improper Authorization via departId Parameter in sysDepartPermission
CVSS 3.1
CVE-2025-15123
LOW
JeecgBoot < 3.9.0 - Improper Authorization via /sys/sysDepartPermission/datarule/
CVSS 3.1
CVE-2025-15122
LOW
JeecgBoot < 3.9.0 - Improper Authorization via DepartId/RoleId Manipulation
CVSS 3.1
CVE-2025-15120
LOW
JeecgBoot < 3.9.0 - Improper Authorization via getDeptRoleList departId Parameter
CVSS 3.1
CVE-2025-15119
LOW
JeecgBoot < 3.9.0 - Improper Authorization in sys/sysDepartRole/list deptId Parameter
CVSS 3.1
CVE-2025-15118
MEDIUM
macrozheng mall < 1.0.3 - Improper Authorization in Member Address Update Endpoint
CVSS 4.3
CVE-2025-15106
MEDIUM
maxun < 0.0.28 - Improper Authorization via Authentication Endpoint
CVSS 6.3
CVE-2025-15087
MEDIUM
youlai-mall 1.0.0/2.0.0 - Improper Authorization via OrderController submitOrderPayment
CVSS 4.3
CVE-2025-15086
MEDIUM
youlai-mall 1.0.0/2.0.0 - Incorrect Privilege Assignment in MemberController
CVSS 4.3
CVE-2025-15085
MEDIUM
youlai-mall 1.0.0/2.0.0 - Incorrect Privilege Assignment in Balance Handler
CVSS 4.3
Details
Vulnerabilities
914