CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,344 vulnerabilities with CWE-862
CVE-2025-1307 CRITICAL
Newscrunch <= 1.8.4.1 - Authenticated Arbitrary File Upload via newscrunch_install_and_activate_plugin
CVSS 9.8
CVE-2025-1639 HIGH
Crowdytheme Arolax < 1.7 - Missing Authorization
CVSS 8.8
CVE-2025-1891 MEDIUM
shishuocms 1.1 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-27270 CRITICAL
NotFound Residential Address Detection <2.5.4 - Privilege Escalation
CVSS 9.8
CVE-2025-23763 MEDIUM
WAH Forms < 1.0 - Missing Authorization
CVSS 6.5
CVE-2025-23615 MEDIUM
NotFound Interactive Page Hierarchy <1.0.1 - Info Disclosure
CVSS 6.5
CVE-2025-23613 MEDIUM
NotFound WP Journal <1.1 - Info Disclosure
CVSS 6.5
CVE-2025-23515 MEDIUM
ts-tree <= 0.1.1 - Unauthenticated Arbitrary Content Deletion
CVSS 6.5
CVE-2025-23440 MEDIUM
radSLIDE <= 2.1 - Missing Authorization to Stored Cross-Site Scripting
CVSS 6.3
CVE-2025-24654 HIGH
SEO Plugin by Squirrly SEO <= 12.4.07 - Missing Authorization
CVSS 7.1
CVE-2025-27583 CRITICAL
Serosoft Academia EagleR 1.0.118 - Missing Authorization in /rest/staffResource/findAllUsersAcrossOrg
CVSS 9.1
CVE-2025-25953 MEDIUM
Academia Student Information System EagleR 1.0.118 - Authenticated Privilege Escalation via Azure JWT Token Exposure
CVSS 6.5
CVE-2025-1813 MEDIUM
zframeworks zz < 2024-8 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-1404 MEDIUM
Secure Copy Content Protection <=4.4.7 - Unauthenticated Email Disclosure
CVSS 5.3
CVE-2025-1502 MEDIUM
IP2Location Redirection <1.33.3 - Info Disclosure
CVSS 5.3
CVE-2025-1780 MEDIUM
WordPress WC4BP <3.4.25 - Privilege Escalation
CVSS 4.3
CVE-2025-1682 HIGH
Cardealer theme <1.6.4 - Privilege Escalation
CVSS 8.8
CVE-2025-1681 MEDIUM
Cardealer WordPress <1.6.4 - Info Disclosure
CVSS 5.4
CVE-2025-1745 MEDIUM
pb-cms 2.0 - Cross-Site Request Forgery in Logout
CVSS 4.3
CVE-2025-22280 HIGH
DefendWP Firewall <= 1.1.0 - Missing Authorization
CVSS 7.6
CVE-2025-1249 MEDIUM
Pixelite Events Manager <6.6.4.1 - Info Disclosure
CVSS 5.3
CVE-2025-1091 MEDIUM
Broken Authorization - Info Disclosure
CVSS 4.3
CVE-2025-27000 MEDIUM
George Pattichis Simple Photo Feed <1.4.0 - Info Disclosure
CVSS 5.4
CVE-2025-26995 MEDIUM
Anton Vanyukov Market Exporter <2.0.21 - Info Disclosure
CVSS 5.4
CVE-2025-26983 MEDIUM
WPZOOM Recipe Card Blocks <3.4.3 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 8,344
Exploit Likelihood High