CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,331 vulnerabilities with CWE-862
CVE-2025-52824 HIGH
MDJM Mobile DJ Manager <1.7.6 - Info Disclosure
CVSS 8.8
CVE-2025-52818 HIGH
Trusty Whistleblowing <1.5.2 - Info Disclosure
CVSS 8.2
CVE-2025-52817 HIGH
ZealousWeb Abandoned Contact Form 7 - Info Disclosure
CVSS 8.2
CVE-2025-5846 LOW
GitLab EE <17.11.5-18.1.1 - Privilege Escalation
CVSS 2.7
CVE-2025-5315 MEDIUM
GitLab 17.2-17.11.5, 18.0-18.0.3, 18.1-18.1.1 - Authenticated Missing Authorization via Crafted API Requests
CVSS 4.3
CVE-2025-5813 MEDIUM
Amazon Products to WooCommerce <1.2.7 - Info Disclosure
CVSS 5.3
CVE-2025-5812 MEDIUM
VG WORT METIS <= 2.0.0 - Authenticated Unauthorized Data Modification via gutenberg_save_post()
CVSS 4.3
CVE-2025-3863 MEDIUM
Post Carousel Slider for Elementor <= 1.6.0 - Authenticated Arbitrary Email Sending via Support Form Handler
CVSS 4.3
CVE-2025-6664 MEDIUM
CodeAstro Patient Record Management System 1.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-52878 MEDIUM
JetBrains TeamCity < 2025.03.3 - Unauthenticated Username Exposure
CVSS 4.3
CVE-2025-6478 MEDIUM
CodeAstro Expense Management System 1.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-6476 MEDIUM
Gym Management System 1.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-5121 HIGH
GitLab 17.11.0-17.11.3 and 18.0.0-18.0.1 - Missing Authorization in Compliance Framework Application
CVSS 8.5
CVE-2025-52802 HIGH
Import YouTube videos as WP Posts <2.1 - RCE
CVSS 7.5
CVE-2025-50034 MEDIUM
Mahmudul Hasan Arif Enhanced Blocks - Info Disclosure
CVSS 6.5
CVE-2025-50010 MEDIUM
Zapier for WordPress <1.5.2 - Info Disclosure
CVSS 5.4
CVE-2025-50009 MEDIUM
Climax Themes Kata Plus <1.5.3 - RCE
CVSS 5.4
CVE-2025-50008 MEDIUM
WooCommerce Manager <1.2.4.5 - Info Disclosure
CVSS 5.4
CVE-2025-49998 MEDIUM
Wetail WooCommerce Fortnox Integration <4.5.5 - Info Disclosure
CVSS 5.4
CVE-2025-49997 MEDIUM
RafflePress <1.12.17 - Info Disclosure
CVSS 5.3
CVE-2025-49996 MEDIUM
osama.esh WP Visitor Statistics <7.8 - RCE
CVSS 5.3
CVE-2025-49993 MEDIUM
Cookie-Script.com <1.2.1 - Info Disclosure
CVSS 5.3
CVE-2025-49991 MEDIUM
WP-Recall <16.26.14 - Info Disclosure
CVSS 5.3
CVE-2025-49990 MEDIUM
ContentStudio <1.3.4 - Info Disclosure
CVSS 5.3
CVE-2025-49989 MEDIUM
App Cheap App Builder <5.5.3 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 8,331
Exploit Likelihood High