CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

914 vulnerabilities with CWE-266
CVE-2025-69292 HIGH
WP Membership <1.6.5 - Privilege Escalation
CVSS 8.8
CVE-2025-69183 HIGH
Hospital Doctor Directory <1.3.9 - Privilege Escalation
CVSS 8.8
CVE-2025-69182 HIGH
e-plugins Institutions Directory <= 1.3.4 - Privilege Escalation
CVSS 8.8
CVE-2025-68869 CRITICAL
LazyTasks <1.4.01 - Privilege Escalation
CVSS 9.8
CVE-2025-68027 HIGH
Themefic Hydra Booking <1.1.32 - Privilege Escalation
CVSS 7.3
CVE-2025-67966 HIGH
Lawyer Directory <1.3.4 - Privilege Escalation
CVSS 8.8
CVE-2025-67953 HIGH
Booking Activities <1.16.44 - Privilege Escalation
CVSS 8.1
CVE-2025-50007 HIGH
Jthemes xSmart <= 1.2.9.4 - Privilege Escalation
CVSS 8.8
CVE-2025-67279 MEDIUM
TIM BPM Suite & TIM FLOW < 9.1.2 - Privilege Escalation via MD5 Password Hash Storage
CVSS 5.3
CVE-2025-67278 MEDIUM
TIM BPM Suite & TIM FLOW < 9.1.2 - Privilege Escalation via Crafted HTTP Request
CVSS 6.5
CVE-2025-31643 HIGH
WPCHURCH <2.7.0 - Privilege Escalation
CVSS 8.8
CVE-2025-29004 HIGH
AA-Team Premium Age Verification/Restriction <3.0.2 - Privilege Esc...
CVSS 8.8
CVE-2025-15213 MEDIUM
Student File Management System 1.0 - Improper Authorization via File Download Handler
CVSS 4.3
CVE-2025-15126 LOW
JeecgBoot < 3.9.0 - Improper Authorization via PositionId Argument in getPositionUserList
CVSS 3.1
CVE-2025-15125 LOW
JeecgBoot < 3.9.0 - Improper Authorization via departId Parameter in queryDepartPermission
CVSS 3.1
CVE-2025-15124 LOW
JeecgBoot < 3.9.0 - Improper Authorization via departId Parameter in sysDepartPermission
CVSS 3.1
CVE-2025-15123 LOW
JeecgBoot < 3.9.0 - Improper Authorization via /sys/sysDepartPermission/datarule/
CVSS 3.1
CVE-2025-15122 LOW
JeecgBoot < 3.9.0 - Improper Authorization via DepartId/RoleId Manipulation
CVSS 3.1
CVE-2025-15120 LOW
JeecgBoot < 3.9.0 - Improper Authorization via getDeptRoleList departId Parameter
CVSS 3.1
CVE-2025-15119 LOW
JeecgBoot < 3.9.0 - Improper Authorization in sys/sysDepartRole/list deptId Parameter
CVSS 3.1
CVE-2025-15118 MEDIUM
macrozheng mall < 1.0.3 - Improper Authorization in Member Address Update Endpoint
CVSS 4.3
CVE-2025-15106 MEDIUM
maxun < 0.0.28 - Improper Authorization via Authentication Endpoint
CVSS 6.3
CVE-2025-15087 MEDIUM
youlai-mall 1.0.0/2.0.0 - Improper Authorization via OrderController submitOrderPayment
CVSS 4.3
CVE-2025-15086 MEDIUM
youlai-mall 1.0.0/2.0.0 - Incorrect Privilege Assignment in MemberController
CVSS 4.3
CVE-2025-15085 MEDIUM
youlai-mall 1.0.0/2.0.0 - Incorrect Privilege Assignment in Balance Handler
CVSS 4.3
Details
Vulnerabilities 914