CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,343 vulnerabilities with CWE-862
CVE-2025-1528 MEDIUM
Search & Filter Pro <2.5.19 - Info Disclosure
CVSS 4.3
CVE-2025-1285 MEDIUM
Resido - Real Estate WordPress Theme <3.6 - Auth Bypass
CVSS 5.3
CVE-2025-0955 MEDIUM
VidoRev Extensions <2.9.9.9.9.5 - Auth Bypass
CVSS 5.3
CVE-2025-27103 MEDIUM
dataease < 2.10.6 - Authenticated Arbitrary File Read and Deserialization via JDBC Connection
CVSS 6.5
CVE-2025-24974 MEDIUM
DataEase < 2.10.6 - Authenticated Arbitrary File Read and Deserialization via JDBC Connection
CVSS 6.5
CVE-2025-2104 MEDIUM
Pagelayer - WordPress <1.9.8 - Privilege Escalation
CVSS 4.3
CVE-2025-1508 MEDIUM
WP Crowdfunding <= 2.1.14 - Authenticated Unauthorized Data Access via download_data Action
CVSS 5.3
CVE-2025-28938 MEDIUM
Bjoern WP Performance Pack <2.5.3 - Info Disclosure
CVSS 4.3
CVE-2025-28920 MEDIUM
Jogesh Responsive Google Map <3.1.5 - RCE
CVSS 5.3
CVE-2025-28872 MEDIUM
Block Spam By Math Reloaded <= 2.2.4 - Missing Authorization
CVSS 5.3
CVE-2025-27432 LOW
SAP Electronic Invoicing for Brazil - Privilege Escalation
CVSS 2.4
CVE-2025-26661 HIGH
SAP NetWeaver - Privilege Escalation
CVSS 8.8
CVE-2025-26656 MEDIUM
SAP S/4HANA Manage Purchasing Info Records - Authenticated Privilege Escalation via OData Service
CVSS 4.3
CVE-2025-26655 LOW
SAP Just In Time - Authenticated Privilege Escalation via Missing Authorization
CVSS 3.1
CVE-2025-25244 MEDIUM
SAP Business Warehouse - Privilege Escalation
CVSS 5.7
CVE-2025-23188 MEDIUM
SAP S/4HANA (RBD) - Authenticated Missing Authorization Check in IBS Module
CVSS 4.3
CVE-2025-1325 MEDIUM
WP-Recall < 16.26.10 - Authenticated Arbitrary Shortcode Execution via rcl_preview_post AJAX Endpoint
CVSS 6.3
CVE-2025-1504 MEDIUM
Post Lockdown < 4.0.2 - Authenticated Information Exposure via pl_autocomplete AJAX Action
CVSS 4.3
CVE-2025-1481 MEDIUM
Shortcode Cleaner Lite <= 1.0.9 - Authenticated Unauthorized Data Access via download_backup Function
CVSS 6.5
CVE-2025-1309 HIGH
UiPress lite - Privilege Escalation
CVSS 8.8
CVE-2025-2042 MEDIUM
huang-yk student-manage 1.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-1666 MEDIUM
Cookiebot CMP <4.4.1 - Info Disclosure
CVSS 4.3
CVE-2025-0954 MEDIUM
WP Online Contract <5.1.4 - Auth Bypass
CVSS 6.5
CVE-2025-27666 CRITICAL
Vasion Print < 20.0.1923 and Virtual Appliance < 22.0.843 - Missing Authorization
CVSS 9.8
CVE-2025-1307 CRITICAL
Newscrunch <= 1.8.4.1 - Authenticated Arbitrary File Upload via newscrunch_install_and_activate_plugin
CVSS 9.8
Details
Vulnerabilities 8,343
Exploit Likelihood High