CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,330 vulnerabilities with CWE-862
CVE-2025-49916 HIGH
MultiVendorX <4.2.23 - Info Disclosure
CVSS 8.6
CVE-2025-49913 MEDIUM
CoSchedule <3.4.0 - Info Disclosure
CVSS 5.3
CVE-2025-49910 HIGH
WPGuppy <= 1.1.4 - Missing Authorization
CVSS 8.2
CVE-2025-49907 MEDIUM
RealMag777 MDTF <= 1.3.3.9 - Privilege Escalation
CVSS 4.3
CVE-2025-49906 MEDIUM
StellarWP WPComplete <= 2.9.5.3 - Info Disclosure
CVSS 5.3
CVE-2025-49903 MEDIUM
bdthemes ZoloBlocks <= 2.3.11 - Privilege Escalation
CVSS 5.3
CVE-2025-49899 MEDIUM
jjlemstra Whydonate <4.0.15 - Info Disclosure
CVSS 5.3
CVE-2025-49377 MEDIUM
Themefic Hydra Booking <= 1.1.9 - Privilege Escalation
CVSS 6.3
CVE-2025-49376 MEDIUM
DELUCKS SEO <= 2.5.9 - Missing Authorization
CVSS 5.3
CVE-2025-48096 MEDIUM
FRESHFACE Custom CSS <= 1.4.0 - Missing Authorization
CVSS 6.5
CVE-2025-30944 HIGH
Tablesome Table Premium <2.1.24 - Info Disclosure
CVSS 7.5
CVE-2025-61755 LOW
Oracle GraalVM for JDK 17.0.16 and 21.0.8 - Unauthenticated Missing Authorization
CVSS 3.7
CVE-2025-61751 HIGH
Oracle Financial Services Analytical Applications Infrastructure 8.0.7.9, 8.0.8.7, 8.1.2.5 - Missing Authorization
CVSS 8.1
CVE-2025-9133 HIGH
Zyxel ATP-USG FLEX-20(W)-VPN - Info Disclosure
CVSS 8.1
CVE-2025-11372 MEDIUM
LearnPress - WordPress LMS Plugin <4.2.9.2 - SQL Injection
CVSS 6.5
CVE-2025-11742 MEDIUM
WPC Smart Wishlist - Info Disclosure
CVSS 4.3
CVE-2025-11378 MEDIUM
ShortPixel Image Optimizer - Info Disclosure
CVSS 5.4
CVE-2025-62642 MEDIUM
Restaurant Brands International Assistant < 2025-09-06 - Unauthenticated Account Creation via Signup API
CVSS 5.8
CVE-2025-58075 HIGH
Mattermost 10.5.0-10.5.10 10.10.0-10.10.2 10.11.0-10.11.1 - Unauthenticated Team Join via RelayState Manipulation
CVSS 8.1
CVE-2025-58073 HIGH
Mattermost 10.5.0-10.5.10 10.10.0-10.10.2 10.11.0-10.11.1 - Unauthenticated Team Join via OAuth State Manipulation
CVSS 8.1
CVE-2025-41410 MEDIUM
Mattermost 10.5.0-10.5.10 10.10.0-10.10.2 10.11.0-10.11.2 - Missing Authorization via Slack Import Process
CVSS 5.4
CVE-2025-41443 MEDIUM
Mattermost 10.5.0-10.5.12 and 10.11.0-10.11.2 - Missing Authorization via Channel IDs Endpoint
CVSS 4.3
CVE-2025-10849 MEDIUM
Felan Framework <1.1.4 - Info Disclosure
CVSS 5.3
CVE-2025-10706 HIGH
Classified Pro <1.0.14 - Privilege Escalation
CVSS 8.8
CVE-2025-11701 MEDIUM
Zip Attachments plugin <1.7 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 8,330
Exploit Likelihood High