CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,331 vulnerabilities with CWE-862
CVE-2025-21416 HIGH
Azure Virtual Desktop - Missing Authorization
CVSS 8.5
CVE-2025-32973 CRITICAL
XWiki 15.9-15.10.12, 16.0.0-16.4.3, 16.5.0-16.8.0-rc-1 - Missing Authorization for Programming Rights
CVSS 9.0
CVE-2025-3953 MEDIUM
WP Statistics < 14.13.3 - Authenticated Arbitrary Plugin Settings Update via optionUpdater Function
CVSS 5.4
CVE-2025-46348 CRITICAL
YesWiki < 4.5.4 - Unauthenticated Backup Archive Creation and Download
CVSS 10.0
CVE-2025-4095 MEDIUM
Registry Access Management - Info Disclosure
CVE-2025-4064 MEDIUM
ScriptAndTools Online-Travling-System 1.0 - Improper Access Control in /admin/viewenquiry.php
CVSS 5.3
CVE-2025-3452 MEDIUM
SecuPress Free < 2.3.9 - Authenticated Arbitrary Plugin Installation via Missing Capability Check
CVSS 4.3
CVE-2025-39367 MEDIUM
SeventhQueen Kleo <5.4.4 - Info Disclosure
CVSS 5.3
CVE-2025-3997 MEDIUM
dazhouda lecms 3.0.3 - Cross-Site Request Forgery via Personal Information Page
CVSS 4.3
CVE-2025-3981 MEDIUM
wowjoy Internet Doctor Workstation System 1.0 - Info Disclosure
CVSS 4.3
CVE-2025-3980 MEDIUM
wowjoy Internet Doctor Workstation System 1.0 - Auth Bypass
CVSS 4.3
CVE-2025-3979 MEDIUM
lecms 3.0.3 - Cross-Site Request Forgery in Password Change Handler
CVSS 4.3
CVE-2025-3977 MEDIUM
iteachyou Dreamer CMS <4.1.3 - Info Disclosure
CVSS 4.3
CVE-2025-3964 MEDIUM
withstars Books-Management-System 1.0 - CSRF
CVSS 4.3
CVE-2025-3963 HIGH
withstars Books-Management-System 1.0 - Info Disclosure
CVSS 7.3
CVE-2025-3960 HIGH
withstars Books-Management-System 1.0 - Info Disclosure
CVSS 7.3
CVE-2025-3959 MEDIUM
withstars Books-Management-System 1.0 - CSRF
CVSS 4.3
CVE-2025-3915 MEDIUM
Aeropage Sync for Airtable <3.2.0 - Info Disclosure
CVSS 4.3
CVE-2025-3906 HIGH
Integração entre Eduzz e Woocommerce - Privilege Escalation
CVSS 8.8
CVE-2025-43862 HIGH
Dify < 0.6.12 - Improper Access Control in APP Orchestration
CVSS 7.6
CVE-2025-32045 MEDIUM
Moodle < 4.1.17 - Missing Authorization in Grade Reports
CVSS 5.3
CVE-2025-3912 MEDIUM
WS Form LITE <= 1.10.35 - Unauthenticated Sensitive Data Exposure
CVSS 5.3
CVE-2025-1279 HIGH
BM Content Builder plugin - Privilege Escalation
CVSS 8.8
CVE-2025-46535 MEDIUM
AlphaEfficiencyTeam Custom Login and Registration <1.0.0 - RCE
CVSS 5.4
CVE-2025-46519 MEDIUM
Media Library Downloader <1.3.1 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 8,331
Exploit Likelihood High