The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,331 vulnerabilities with CWE-862
CVE-2025-52824
HIGH
MDJM Mobile DJ Manager <1.7.6 - Info Disclosure
CVSS 8.8
CVE-2025-52818
HIGH
Trusty Whistleblowing <1.5.2 - Info Disclosure
CVSS 8.2
CVE-2025-52817
HIGH
ZealousWeb Abandoned Contact Form 7 - Info Disclosure
CVSS 8.2
CVE-2025-5846
LOW
GitLab EE <17.11.5-18.1.1 - Privilege Escalation
CVSS 2.7
CVE-2025-5315
MEDIUM
GitLab 17.2-17.11.5, 18.0-18.0.3, 18.1-18.1.1 - Authenticated Missing Authorization via Crafted API Requests
CVSS 4.3
CVE-2025-5813
MEDIUM
Amazon Products to WooCommerce <1.2.7 - Info Disclosure
CVSS 5.3
CVE-2025-5812
MEDIUM
VG WORT METIS <= 2.0.0 - Authenticated Unauthorized Data Modification via gutenberg_save_post()
CVSS 4.3
CVE-2025-3863
MEDIUM
Post Carousel Slider for Elementor <= 1.6.0 - Authenticated Arbitrary Email Sending via Support Form Handler
CVSS 4.3
CVE-2025-6664
MEDIUM
CodeAstro Patient Record Management System 1.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-52878
MEDIUM
JetBrains TeamCity < 2025.03.3 - Unauthenticated Username Exposure
CVSS 4.3
CVE-2025-6478
MEDIUM
CodeAstro Expense Management System 1.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-6476
MEDIUM
Gym Management System 1.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-5121
HIGH
GitLab 17.11.0-17.11.3 and 18.0.0-18.0.1 - Missing Authorization in Compliance Framework Application
CVSS 8.5
CVE-2025-52802
HIGH
Import YouTube videos as WP Posts <2.1 - RCE
CVSS 7.5
CVE-2025-50034
MEDIUM
Mahmudul Hasan Arif Enhanced Blocks - Info Disclosure
CVSS 6.5
CVE-2025-50010
MEDIUM
Zapier for WordPress <1.5.2 - Info Disclosure
CVSS 5.4
CVE-2025-50009
MEDIUM
Climax Themes Kata Plus <1.5.3 - RCE
CVSS 5.4
CVE-2025-50008
MEDIUM
WooCommerce Manager <1.2.4.5 - Info Disclosure
CVSS 5.4
CVE-2025-49998
MEDIUM
Wetail WooCommerce Fortnox Integration <4.5.5 - Info Disclosure
CVSS 5.4
CVE-2025-49997
MEDIUM
RafflePress <1.12.17 - Info Disclosure
CVSS 5.3
CVE-2025-49996
MEDIUM
osama.esh WP Visitor Statistics <7.8 - RCE
CVSS 5.3
CVE-2025-49993
MEDIUM
Cookie-Script.com <1.2.1 - Info Disclosure
CVSS 5.3
CVE-2025-49991
MEDIUM
WP-Recall <16.26.14 - Info Disclosure
CVSS 5.3
CVE-2025-49990
MEDIUM
ContentStudio <1.3.4 - Info Disclosure
CVSS 5.3
CVE-2025-49989
MEDIUM
App Cheap App Builder <5.5.3 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
8,331
Exploit Likelihood
High