CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,343 vulnerabilities with CWE-862
CVE-2025-24245 CRITICAL
macOS < 15.4 - Unauthorized Password Access via Verification Code Delay Bypass
CVSS 9.8
CVE-2025-24181 CRITICAL
macOS < 13.7.5, < 14.7.5, < 15.4 - Unprotected User Data Exposure via Permissions Issue
CVSS 9.8
CVE-2025-31691 CRITICAL
Drupal OAuth2 Server <2.1.0 - Info Disclosure
CVSS 9.8
CVE-2025-31686 HIGH
Drupal Open Social <12.3.11-12.4.10 - Forceful Browsing
CVSS 8.1
CVE-2025-31685 CRITICAL
Drupal Open Social <12.3.11-12.4.10 - Forceful Browsing
CVSS 9.1
CVE-2025-31681 CRITICAL
Drupal Authenticator Login <2.0.6 - Forceful Browsing
CVSS 9.8
CVE-2025-31678 HIGH
Drupal AI <1.0.3 - Forceful Browsing
CVSS 8.2
CVE-2025-31618 MEDIUM
Jaap Jansma Connector to CiviCRM <1.0.9 - Privilege Escalation
CVSS 5.3
CVE-2025-31611 MEDIUM
Shaharia Azam Auto Post After Image Upload <1.6 - RCE
CVSS 4.3
CVE-2025-31609 MEDIUM
Arni Cinco WPCargo Track & - Info Disclosure
CVSS 4.3
CVE-2025-31606 MEDIUM
softpulseinfotech SP Blog Designer - Info Disclosure
CVSS 4.8
CVE-2025-31603 MEDIUM
Moshensky CF7 Spreadsheets <2.3.2 - Info Disclosure
CVSS 5.4
CVE-2025-31596 MEDIUM
Chatwee Chat <2.1.3 - Info Disclosure
CVSS 4.3
CVE-2025-31584 MEDIUM
Elfsight Testimonials Slider <1.0.1 - Info Disclosure
CVSS 5.4
CVE-2025-31576 MEDIUM
PostmarkApp Email Integrator <2.4 - RCE
CVSS 4.3
CVE-2025-31555 MEDIUM
ContentMX Content Publisher <1.0.6 - RCE
CVSS 5.4
CVE-2025-31546 MEDIUM
WP Messiah Swiss Toolkit For WP <1.3.0 - Info Disclosure
CVSS 4.3
CVE-2025-31545 MEDIUM
WP Messiah Safe Ai Malware Protection <1.0.20 - Info Disclosure
CVSS 5.4
CVE-2025-31544 MEDIUM
WP Messiah Swiss Toolkit For WP <1.3.0 - Info Disclosure
CVSS 4.3
CVE-2025-31540 MEDIUM
ACME Divi Modules <1.3.5 - Info Disclosure
CVSS 4.3
CVE-2025-31539 MEDIUM
Blocksera Cryptocurrency Widgets Pack <2.0.1 - Info Disclosure
CVSS 6.5
CVE-2025-31533 MEDIUM
Salesmate Add-On for Gravity Forms <2.0.3 - Info Disclosure
CVSS 5.3
CVE-2025-31530 MEDIUM
Google SEO Pressor Snippet <2.0 - RCE
CVSS 4.3
CVE-2025-31529 MEDIUM
Slider Path for Elementor <3.0.0 - Info Disclosure
CVSS 4.3
CVE-2025-31528 MEDIUM
wokamoto StaticPress <0.4.5 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 8,343
Exploit Likelihood High