The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,344 vulnerabilities with CWE-862
CVE-2025-24693
MEDIUM
Yehi Advanced Notifications <1.2.7 - Info Disclosure
CVSS 4.3
CVE-2025-24691
MEDIUM
Gagan Sandhu, Enej Bajgoric, CTLT DEV, UBC People Lists <1.3.10 - I...
CVSS 4.3
CVE-2025-24682
MEDIUM
mikemmx Super Block Slider <2.7.9 - Info Disclosure
CVSS 4.3
CVE-2025-24679
MEDIUM
webraketen Internal Links Manager <2.5.2 - Info Disclosure
CVSS 4.3
CVE-2025-24652
MEDIUM
WP Duplicate - WordPress Migration Plugin <= 1.1.6 - Missing Authorization
CVSS 5.4
CVE-2025-24649
MEDIUM
wpase.com ASE <7.6.2 - Info Disclosure
CVSS 4.3
CVE-2025-24633
MEDIUM
silverplugins217 - Privilege Escalation
CVSS 5.3
CVE-2025-24625
MEDIUM
Marco Almeida | Webdados Taxonomy/Term and Role based Discounts for...
CVSS 4.3
CVE-2025-24618
MEDIUM
Element Invader Addons for Elementor <= 1.3.1 - Missing Authorization
CVSS 4.3
CVE-2025-24613
MEDIUM
Foliovision FV Thoughtful Comments <0.3.5 - Info Disclosure
CVSS 4.3
CVE-2025-24604
MEDIUM
Vikas Ratudi VForm <3.0.5 - Info Disclosure
CVSS 5.4
CVE-2025-24596
MEDIUM
WooCommerce Product Table Lite <= 3.8.7 - Missing Authorization
CVSS 5.3
CVE-2025-24594
MEDIUM
Speedcomp Linet ERP-Woocommerce Integration <3.5.7 - Info Disclosure
CVSS 6.5
CVE-2025-24591
MEDIUM
Ninja Team GDPR CCPA Compliance Support <= 2.7.1 - Missing Authorization
CVSS 4.3
CVE-2025-24589
MEDIUM
JSM Show Post Metadata <4.6.0 - Info Disclosure
CVSS 4.3
CVE-2025-24588
MEDIUM
Patreon WordPress <1.9.1 - Info Disclosure
CVSS 6.5
CVE-2025-24580
MEDIUM
Code for Recovery <3.16.5 - Info Disclosure
CVSS 6.5
CVE-2025-24571
MEDIUM
Epsiloncool WP Fast Total Search <1.78.258 - Info Disclosure
CVSS 5.4
CVE-2025-22612
CRITICAL
Coolify < 4.0.0-beta.374 - Authenticated Private Key Exposure and Remote Command Execution
CVSS 10.0
CVE-2025-22611
CRITICAL
Coolify < 4.0.0-beta.361 - Authenticated Privilege Escalation and Remote Command Execution
CVSS 9.9
CVE-2025-22610
MEDIUM
Coolify < 4.0.0-beta.361 - Authenticated Missing Authorization for OAuth Configuration
CVSS 6.5
CVE-2025-22609
CRITICAL
Coolify < 4.0.0-beta.361 - Authenticated Private Key Attachment and Remote Command Execution
CVSS 10.0
CVE-2025-22608
MEDIUM
Coolify < 4.0.0-beta.361 - Authenticated Denial of Service via Team Invitation Revocation
CVSS 6.5
CVE-2025-23991
MEDIUM
Product Size Charts Plugin for WooCommerce <2.4.5 - Info Disclosure
CVSS 4.3
CVE-2025-22607
MEDIUM
Coolify < 4.0.0-beta.361 - Authenticated Information Disclosure via GitHub/GitLab Configuration UUID
CVSS 5.5
Details
Vulnerabilities
8,344
Exploit Likelihood
High