CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,330 vulnerabilities with CWE-862
CVE-2025-11692 MEDIUM
Zip Attachments plugin <1.7 - Info Disclosure
CVSS 5.3
CVE-2025-10648 MEDIUM
YourMembership YM SSO Login <1.1.7 - Info Disclosure
CVSS 5.3
CVE-2025-10313 HIGH
Find And Replace content for WordPress <= 1.1 - Unauthenticated Stored XSS and Arbitrary Content Replacement
CVSS 7.2
CVE-2025-10303 MEDIUM
Library Management System <3.1 - Info Disclosure
CVSS 4.3
CVE-2025-10299 HIGH
WPBifröst Plugin <1.0.7 - Privilege Escalation
CVSS 8.8
CVE-2025-10186 MEDIUM
WhyDonate <= 4.0.15 - Unauthenticated Data Deletion via remove_row
CVSS 5.3
CVE-2025-33182 HIGH
NVIDIA Jetson Linux - Privilege Escalation
CVSS 7.6
CVE-2025-10732 MEDIUM
WordPress SureForms <1.12.2 - Info Disclosure
CVSS 4.3
CVE-2025-8682 MEDIUM
Newsup theme <5.0.10 - Unauth Plugin Install
CVSS 4.3
CVE-2025-8593 HIGH
GSheetConnector For Gravity Forms <1.3.27 - Auth Bypass
CVSS 8.8
CVE-2025-11380 MEDIUM
Everest Backup - WordPress Cloud Backup, Migration, Restore & Cloni...
CVSS 5.9
CVE-2025-9549 MEDIUM
Drupal Facets <2.0.10-3.0.1 - Forceful Browsing
CVSS 6.5
CVE-2025-11581 MEDIUM
PowerJob < 5.1.2 - Missing Authorization in OpenAPIController
CVSS 5.3
CVE-2025-11580 MEDIUM
PowerJob < 5.1.2 - Unauthenticated Missing Authorization in /user/list Endpoint
CVSS 5.3
CVE-2025-8887 MEDIUM
Usta Information Systems Inc. Aybs Interaktif - Info Disclosure
CVSS 6.1
CVE-2025-8886 MEDIUM
Usta Information Systems Inc. Aybs Interaktif - Privilege Escalation
CVSS 6.7
CVE-2025-59968 HIGH
Juniper Space Security Director < 24.1R3 Patch V4 - Unauthenticated Metadata Read and Modify via Web Interface
CVSS 8.6
CVE-2025-10352 CRITICAL
Melis Platform < 5.3.11 - Unauthenticated Administrator Account Creation via ToolUser Endpoint
CVE-2025-11442 MEDIUM
JhumanJ OpnForm < 1.9.3 - Cross-Site Request Forgery via API Endpoint
CVSS 4.3
CVE-2025-11439 MEDIUM
JhumanJ OpnForm <1.9.3 - Auth Bypass
CVSS 4.3
CVE-2025-11438 MEDIUM
JhumanJ OpnForm <1.9.3 - Auth Bypass
CVSS 6.3
CVE-2025-9243 HIGH
WordPress Cost Calculator Builder <3.5.32 - Info Disclosure
CVSS 8.1
CVE-2025-9029 MEDIUM
WDesignKit <= 1.2.16 - Unauthenticated Missing Authorization via wdkit_handle_review_submission
CVSS 4.3
CVE-2025-11228 MEDIUM
GiveWP - Donation Plugin - Info Disclosure
CVSS 5.3
CVE-2025-9194 MEDIUM
Constructor Theme <1.6.5 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 8,330
Exploit Likelihood High