CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,331 vulnerabilities with CWE-862
CVE-2025-48116 MEDIUM
EventON <= 2.4.4 - Missing Authorization
CVSS 5.3
CVE-2025-48079 MEDIUM
Metagauss ProfileGrid <5.9.5.1 - Info Disclosure
CVSS 4.3
CVE-2025-47564 MEDIUM
ashanjay EventON <= 4.9.8 - Missing Authorization
CVSS 5.3
CVE-2025-47563 MEDIUM
villatheme CURCY <2.3.7 - Info Disclosure
CVSS 5.3
CVE-2025-47560 MEDIUM
MapSVG < 8.6.13 - Missing Authorization
CVSS 5.0
CVE-2025-47556 MEDIUM
QuanticaLabs CSS3 Compare Pricing Tables <11.5 - Info Disclosure
CVSS 5.4
CVE-2025-47534 MEDIUM
ValvePress Wordpress Auto Spinner <3.25.0 - Info Disclosure
CVSS 4.3
CVE-2025-39511 MEDIUM
ValvePress Pinterest Automatic Pin <4.18.2 - Info Disclosure
CVSS 4.3
CVE-2025-39493 MEDIUM
ValvePress Rankie < 1.8.2 - Missing Authorization
CVSS 4.3
CVE-2025-39482 MEDIUM
imithemes Eventer < 3.11.4 - Missing Authorization
CVSS 4.3
CVE-2025-32296 MEDIUM
quantumcloud Simple Link Directory Pro <14.7.3 - Info Disclosure
CVSS 5.3
CVE-2025-32295 MEDIUM
WordPresschef Salon Booking Pro <10.10.2 - RCE
CVSS 4.3
CVE-2025-31923 MEDIUM
QuanticaLabs CSS3 Accordions <3.0 - Info Disclosure
CVSS 5.4
CVE-2025-31630 MEDIUM
The Business <1.6.1 - Info Disclosure
CVSS 5.3
CVE-2025-31071 MEDIUM
HotStar - Multi-Purpose Business Theme <1.4 - Info Disclosure
CVSS 5.3
CVE-2025-31066 MEDIUM
themeton Acerola <= 1.6.5 - Missing Authorization
CVSS 5.3
CVE-2025-31065 MEDIUM
Rozario < 1.4 - Missing Authorization
CVSS 5.3
CVE-2025-31063 MEDIUM
redqteam Wishlist <2.1.0 - Info Disclosure
CVSS 4.3
CVE-2025-47792 MEDIUM
Nextcloud Desktop < 3.15.0 - Unauthenticated Improper Access Control via Socket API
CVSS 5.0
CVE-2025-3624 MEDIUM
Hitachi Ops Center Analyzer <11.0.4.00 - Info Disclosure
CVSS 4.3
CVE-2025-47580 MEDIUM
Front End Users <= 3.2.35 - Missing Authorization
CVSS 5.4
CVE-2025-47887 MEDIUM
Jenkins Cadence vManager < 4.0.1-286.v9e25a_740b_a_48 - Missing Authorization
CVSS 4.3
CVE-2025-47709 MEDIUM
miniorange_2fa 5.0.0-5.2.0 - Missing Authorization
CVSS 6.5
CVE-2025-24021 MEDIUM
iTop < 2.7.12 - Authenticated Missing Authorization
CVSS 5.0
CVE-2025-4430 HIGH
EZD RP < 20.19 - Unauthenticated File Manipulation via Token Endpoint
Details
Vulnerabilities 8,331
Exploit Likelihood High