CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,344 vulnerabilities with CWE-862
CVE-2025-23187 MEDIUM
SAP NetWeaver/ABAP Platform < ST-PI 2008_1_700/710/740 - Unauthenticated Missing Authorization in SDCCN
CVSS 5.3
CVE-2025-25167 HIGH
BookPress - For Book Authors <1.2.7 - Info Disclosure
CVSS 8.2
CVE-2025-25120 MEDIUM
Melodic Media Slide Banners <1.3 - Info Disclosure
CVSS 4.3
CVE-2025-25110 MEDIUM
Metagauss Event Kikfyre <2.1.8 - Info Disclosure
CVSS 5.4
CVE-2025-25081 MEDIUM
DeannaS Embed RSS <3.1 - Info Disclosure
CVSS 4.2
CVE-2025-1084 MEDIUM
Mindskip xzs-mysql 3.9.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-1074 MEDIUM
Webkul QloApps 1.6.1 - Cross-Site Request Forgery via Logout Function
CVSS 4.3
CVE-2025-20125 CRITICAL
Cisco Identity Services Engine - Authenticated Information Disclosure and Configuration Modification via API
CVSS 9.1
CVE-2025-22730 MEDIUM
Ksher <= 1.1.2 - Missing Authorization
CVSS 6.5
CVE-2025-22696 MEDIUM
EmbedPress Document Block - Upload & Embed Docs <1.1.0 - Info Discl...
CVSS 5.4
CVE-2025-22643 MEDIUM
FameThemes OnePress <2.3.11 - Info Disclosure
CVSS 4.3
CVE-2025-24697 MEDIUM
Realwebcare Image Gallery - Responsive Photo Gallery <1.0.5 - Info ...
CVSS 6.5
CVE-2025-24643 MEDIUM
WPGuppy <= 1.1.0 - Missing Authorization
CVSS 6.5
CVE-2025-24642 MEDIUM
Setup Default Featured Image <= 1.2 - Missing Authorization
CVSS 6.5
CVE-2025-23527 MEDIUM
WC Wallet <= 2.2.0 - Unauthenticated Arbitrary Content Deletion
CVSS 6.5
CVE-2025-22694 MEDIUM
theDotstore Hide Shipping Method For WooCommerce <1.5.0 - Info Disc...
CVSS 4.3
CVE-2025-22686 MEDIUM
CF7 Google Sheets Connector <= 5.0.17 - Missing Authorization
CVSS 5.3
CVE-2025-22681 MEDIUM
Xfinity Soft Content Cloner <1.0.1 - Info Disclosure
CVSS 4.3
CVE-2025-22677 MEDIUM
UIUX Lab Uix Shortcodes <2.0.3 - Info Disclosure
CVSS 4.8
CVE-2025-22260 MEDIUM
Pixelite Meta Tag Manager <3.1 - Info Disclosure
CVSS 4.3
CVE-2025-0939 MEDIUM
MagicForm <= 1.6.2 - Authenticated Data Access and Modification via Missing Capability Check
CVSS 6.3
CVE-2025-22720 MEDIUM
MagePeople Team Booking & Rental Mgr <2.2.1 - Info Disclosure
CVSS 5.8
CVE-2025-22265 MEDIUM
mgplugin EMI Calculator - Info Disclosure
CVSS 6.5
CVE-2025-21396 HIGH
Microsoft Account - Missing Authorization
CVSS 8.2
CVE-2025-24143 MEDIUM
Safari < 18.3 - Unauthenticated User Fingerprinting via File System Access
CVSS 6.5
Details
Vulnerabilities 8,344
Exploit Likelihood High