The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,807 vulnerabilities with CWE-862
CVE-2026-54695
HIGH
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
CVSS 7.5
CVE-2026-54005
HIGH
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
CVE-2026-54004
MEDIUM
Kirby: Access to files of top-level drafts is not protected by permissions
CVE-2026-49274
MEDIUM
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
CVE-2026-59227
MEDIUM
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
CVSS 4.3
CVE-2026-59226
LOW
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
CVSS 3.1
CVE-2026-59225
MEDIUM
Open WebUI: Arena task endpoints can bypass underlying model access controls
CVSS 5.4
CVE-2026-59217
MEDIUM
Open WebUI < 0.10.0 - Knowledge Base Write-Access Bypass
CVSS 4.3
CVE-2026-59216
HIGH
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
CVSS 7.7
CVE-2026-12593
HIGH
Privilege escalation via forged API token creation in Axivion Dashboard OIDC/OAuth2/SSO subsystem
CVE-2026-9240
MEDIUM
Colissimo for WooCommerce <= 2.9.0 - Subscriber Order Shipment Modification
CVSS 4.3
CVE-2026-9237
MEDIUM
Employee, Leave And Recruitment Management System < 1.2.2 - Authorization Bypass
CVSS 4.3
CVE-2026-9235
MEDIUM
DHL eCommerce (Benelux) for WooCommerce <= 2.2.3 - Subscriber Shipping Label Changes
CVSS 4.3
CVE-2026-9028
MEDIUM
CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Missing Authorization to Unauthenticated Arbitrary Order Cancellation via 'order_number' Parameter
CVSS 5.3
CVE-2026-9021
MEDIUM
Easy Invoice <= 2.1.19 - Unauthenticated Quote Approval and Invoice Creation
CVSS 5.3
CVE-2026-4298
MEDIUM
DSGVO All in one for WP <= 4.9 - Missing Authorization to Authenticated (Subscriber+) Settings Reset
CVSS 4.3
CVE-2026-12428
MEDIUM
Blocks for ACF Fields <= 1.6.2 - Missing Authorization to Authenticated (Author+) Arbitrary ACF Field Value Disclosure via 'id' Parameter
CVSS 6.5
CVE-2026-8996
MEDIUM
Backup And Staging BY WP Time Capsule < 1.22.26 - Information Exposure
CVSS 6.5
CVE-2026-8848
HIGH
Popup Maker < 1.22.0 - Remote Code Execution
CVSS 7.2
CVE-2026-7558
MEDIUM
Token of Trust Age Verification <= 4.0.2 - Unauthenticated Donation Data Exposure
CVSS 5.3
CVE-2026-14245
CRITICAL
miniOrange OTP Login, Verification and SMS Notifications <= 5.5.1 - Authentication Bypass to Administrator Account Takeover via 'username_b' Parameter
CVSS 9.8
CVE-2026-12406
MEDIUM
User Frontend <= 4.3.7 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'attach_id' Parameter
CVSS 5.3
CVE-2026-11359
MEDIUM
Memberships and User Profiles for WooCommerce <= 3.4 - Missing Authorization to Authenticated (Subscriber+) ProfileGrid Plugin Installation and Activation
CVSS 4.3
CVE-2026-48492
MEDIUM
Snipe-IT's selectlist visibility is too permissive
CVSS 6.5
CVE-2026-35552
HIGH
CAXperts UPVWebServices 2.4.2212.603-2.7.6 & UDiTH Portal 2026.0.0-2026.2.0 Authenticated License Deactivation via API
CVSS 8.1
Details
Vulnerabilities
8,807
Exploit Likelihood
High