CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,330 vulnerabilities with CWE-862
CVE-2025-22439 HIGH
Android - Missing Authorization in ActionHandler onLastAccessedStackLoaded
CVSS 7.3
CVE-2025-6685 HIGH
ATEN eco DC < 1.2.116 - Authenticated Privilege Escalation via Missing Authorization
CVSS 8.8
CVE-2025-9747 MEDIUM
Koillection < 1.7.0 - Cross-Site Request Forgery in CSRF Protection Controller
CVSS 4.3
CVE-2025-54943 CRITICAL
SUNNET Corporate Training Management System < 10.11 - Missing Authorization for Application Deployment
CVSS 9.8
CVE-2025-43773 CRITICAL
Liferay Portal 7.4.0-7.4.3.132 and Liferay DXP 2024.Q1.1-2024.Q1.18 - Missing Authorization via expandoTableLocalService
CVSS 9.1
CVE-2025-58334 HIGH
JetBrains IDE Services <2025.5.0.1086 - Privilege Escalation
CVSS 8.1
CVE-2025-54734 MEDIUM
B Slider <= 1.1.30 - Missing Authorization
CVSS 5.8
CVE-2025-54733 MEDIUM
Miles All Bootstrap Blocks <1.3.28 - RCE
CVSS 6.5
CVE-2025-54714 HIGH
Dylan James Zephyr Project Manager <3.3.201 - Info Disclosure
CVSS 7.1
CVE-2025-54710 HIGH
bPlugins Tiktok Feed <1.0.21 - Info Disclosure
CVSS 7.1
CVE-2025-53337 MEDIUM
Ashan Perera LifePress <2.1.3 - Info Disclosure
CVSS 5.4
CVE-2025-53230 HIGH
Page Manager for Elementor <2.0.5 - Privilege Escalation
CVSS 7.6
CVE-2025-48350 MEDIUM
Neuralabz LTD AutoWP <2.2.2 - Info Disclosure
CVSS 4.3
CVE-2025-48327 MEDIUM
inkthemes WP Mailgun SMTP <1.0.7 - Info Disclosure
CVSS 5.3
CVE-2025-7956 MEDIUM
Ajax Search Lite <4.13.1 - Info Disclosure
CVSS 5.3
CVE-2025-0951 MEDIUM
WordPress by LiquidThemes - Privilege Escalation
CVSS 4.3
CVE-2025-2246 MEDIUM
GitLab < 18.1.5, 18.2 < 18.2.5, 18.3 < 18.3.1 - Unauthenticated Sensitive CI/CD Variable Exposure via GraphQL API
CVSS 5.8
CVE-2025-58201 MEDIUM
AfterShip <1.17.17 - Info Disclosure
CVSS 5.3
CVE-2025-58198 MEDIUM
Xpro Theme Builder <1.2.9 - Info Disclosure
CVSS 6.5
CVE-2025-58193 MEDIUM
Uncanny Automator <6.7.0.1 - Info Disclosure
CVSS 4.3
CVE-2025-58192 MEDIUM
WP Bulk Delete <= 1.3.6 - Missing Authorization
CVSS 4.3
CVE-2025-0086 MEDIUM
AccountManagerService - Info Disclosure
CVSS 6.2
CVE-2025-48108 MEDIUM
Mojoomla School Management <93.2.0 - Info Disclosure
CVSS 6.5
CVE-2025-7828 MEDIUM
WP Filter & Combine RSS Feeds <0.5 - Info Disclosure
CVSS 4.3
CVE-2025-7827 MEDIUM
Ni WooCommerce Customer Product Report <1.2.4 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 8,330
Exploit Likelihood High