The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,330 vulnerabilities with CWE-862
CVE-2025-49916
HIGH
MultiVendorX <4.2.23 - Info Disclosure
CVSS 8.6
CVE-2025-49913
MEDIUM
CoSchedule <3.4.0 - Info Disclosure
CVSS 5.3
CVE-2025-49910
HIGH
WPGuppy <= 1.1.4 - Missing Authorization
CVSS 8.2
CVE-2025-49907
MEDIUM
RealMag777 MDTF <= 1.3.3.9 - Privilege Escalation
CVSS 4.3
CVE-2025-49906
MEDIUM
StellarWP WPComplete <= 2.9.5.3 - Info Disclosure
CVSS 5.3
CVE-2025-49903
MEDIUM
bdthemes ZoloBlocks <= 2.3.11 - Privilege Escalation
CVSS 5.3
CVE-2025-49899
MEDIUM
jjlemstra Whydonate <4.0.15 - Info Disclosure
CVSS 5.3
CVE-2025-49377
MEDIUM
Themefic Hydra Booking <= 1.1.9 - Privilege Escalation
CVSS 6.3
CVE-2025-49376
MEDIUM
DELUCKS SEO <= 2.5.9 - Missing Authorization
CVSS 5.3
CVE-2025-48096
MEDIUM
FRESHFACE Custom CSS <= 1.4.0 - Missing Authorization
CVSS 6.5
CVE-2025-30944
HIGH
Tablesome Table Premium <2.1.24 - Info Disclosure
CVSS 7.5
CVE-2025-61755
LOW
Oracle GraalVM for JDK 17.0.16 and 21.0.8 - Unauthenticated Missing Authorization
CVSS 3.7
CVE-2025-61751
HIGH
Oracle Financial Services Analytical Applications Infrastructure 8.0.7.9, 8.0.8.7, 8.1.2.5 - Missing Authorization
CVSS 8.1
CVE-2025-9133
HIGH
Zyxel ATP-USG FLEX-20(W)-VPN - Info Disclosure
CVSS 8.1
CVE-2025-11372
MEDIUM
LearnPress - WordPress LMS Plugin <4.2.9.2 - SQL Injection
CVSS 6.5
CVE-2025-11742
MEDIUM
WPC Smart Wishlist - Info Disclosure
CVSS 4.3
CVE-2025-11378
MEDIUM
ShortPixel Image Optimizer - Info Disclosure
CVSS 5.4
CVE-2025-62642
MEDIUM
Restaurant Brands International Assistant < 2025-09-06 - Unauthenticated Account Creation via Signup API
CVSS 5.8
CVE-2025-58075
HIGH
Mattermost 10.5.0-10.5.10 10.10.0-10.10.2 10.11.0-10.11.1 - Unauthenticated Team Join via RelayState Manipulation
CVSS 8.1
CVE-2025-58073
HIGH
Mattermost 10.5.0-10.5.10 10.10.0-10.10.2 10.11.0-10.11.1 - Unauthenticated Team Join via OAuth State Manipulation
CVSS 8.1
CVE-2025-41410
MEDIUM
Mattermost 10.5.0-10.5.10 10.10.0-10.10.2 10.11.0-10.11.2 - Missing Authorization via Slack Import Process
CVSS 5.4
CVE-2025-41443
MEDIUM
Mattermost 10.5.0-10.5.12 and 10.11.0-10.11.2 - Missing Authorization via Channel IDs Endpoint
CVSS 4.3
CVE-2025-10849
MEDIUM
Felan Framework <1.1.4 - Info Disclosure
CVSS 5.3
CVE-2025-10706
HIGH
Classified Pro <1.0.14 - Privilege Escalation
CVSS 8.8
CVE-2025-11701
MEDIUM
Zip Attachments plugin <1.7 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
8,330
Exploit Likelihood
High