CWE-266

Incorrect Privilege Assignment

Parent: CWE-269 - Improper Privilege Management

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

815 vulnerabilities with CWE-266
CVE-2025-14778 MEDIUM
Org.keycloak Keycloak-services - Incorrect Privilege Assignment
CVSS 5.4
CVE-2025-13881 LOW
Org.keycloak Keycloak-services - Incorrect Privilege Assignment
CVSS 2.7
CVE-2025-69293 HIGH
e-plugins Final User <= 1.2.5 - Privilege Escalation
CVSS 8.8
CVE-2025-69292 HIGH
WP Membership <1.6.5 - Privilege Escalation
CVSS 8.8
CVE-2025-69183 HIGH
Hospital Doctor Directory <1.3.9 - Privilege Escalation
CVSS 8.8
CVE-2025-69182 HIGH
e-plugins Institutions Directory <= 1.3.4 - Privilege Escalation
CVSS 8.8
CVE-2025-68869 CRITICAL
LazyTasks <1.4.01 - Privilege Escalation
CVSS 9.8
CVE-2025-68027 HIGH
Themefic Hydra Booking <1.1.32 - Privilege Escalation
CVSS 7.3
CVE-2025-67966 HIGH
Lawyer Directory <1.3.4 - Privilege Escalation
CVSS 8.8
CVE-2025-67953 HIGH
Booking Activities <1.16.44 - Privilege Escalation
CVSS 8.1
CVE-2025-50007 HIGH
Jthemes xSmart <= 1.2.9.4 - Privilege Escalation
CVSS 8.8
CVE-2025-67279 MEDIUM
Tim-solutions Tim Flow < 9.1.2 - Incorrect Privilege Assignment
CVSS 5.3
CVE-2025-67278 MEDIUM
Tim-solutions Tim Flow < 9.1.2 - Incorrect Privilege Assignment
CVSS 6.5
CVE-2025-31643 HIGH
WPCHURCH <2.7.0 - Privilege Escalation
CVSS 8.8
CVE-2025-29004 HIGH
AA-Team Premium Age Verification/Restriction <3.0.2 - Privilege Esc...
CVSS 8.8
CVE-2025-15213 MEDIUM
Fabian Student File Management System - Improper Authorization
CVSS 4.3
CVE-2025-15126 LOW
Jeecg Boot < 3.9.0 - Incorrect Authorization
CVSS 3.1
CVE-2025-15125 LOW
Jeecg Boot < 3.9.0 - Incorrect Authorization
CVSS 3.1
CVE-2025-15124 LOW
Jeecg Boot < 3.9.0 - Incorrect Authorization
CVSS 3.1
CVE-2025-15123 LOW
Jeecg Boot < 3.9.0 - Incorrect Authorization
CVSS 3.1
CVE-2025-15122 LOW
Jeecg Boot < 3.9.0 - Incorrect Authorization
CVSS 3.1
CVE-2025-15120 LOW
Jeecg Boot < 3.9.0 - Incorrect Authorization
CVSS 3.1
CVE-2025-15119 LOW
Jeecg Boot < 3.9.0 - Incorrect Authorization
CVSS 3.1
CVE-2025-15118 MEDIUM
Macrozheng Mall < 1.0.3 - Improper Authorization
CVSS 4.3
CVE-2025-15106 MEDIUM
Maxun < 0.0.28 - Improper Authorization
CVSS 6.3
Details
Vulnerabilities 815