CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,344 vulnerabilities with CWE-862
CVE-2025-24693 MEDIUM
Yehi Advanced Notifications <1.2.7 - Info Disclosure
CVSS 4.3
CVE-2025-24691 MEDIUM
Gagan Sandhu, Enej Bajgoric, CTLT DEV, UBC People Lists <1.3.10 - I...
CVSS 4.3
CVE-2025-24682 MEDIUM
mikemmx Super Block Slider <2.7.9 - Info Disclosure
CVSS 4.3
CVE-2025-24679 MEDIUM
webraketen Internal Links Manager <2.5.2 - Info Disclosure
CVSS 4.3
CVE-2025-24652 MEDIUM
WP Duplicate - WordPress Migration Plugin <= 1.1.6 - Missing Authorization
CVSS 5.4
CVE-2025-24649 MEDIUM
wpase.com ASE <7.6.2 - Info Disclosure
CVSS 4.3
CVE-2025-24633 MEDIUM
silverplugins217 - Privilege Escalation
CVSS 5.3
CVE-2025-24625 MEDIUM
Marco Almeida | Webdados Taxonomy/Term and Role based Discounts for...
CVSS 4.3
CVE-2025-24618 MEDIUM
Element Invader Addons for Elementor <= 1.3.1 - Missing Authorization
CVSS 4.3
CVE-2025-24613 MEDIUM
Foliovision FV Thoughtful Comments <0.3.5 - Info Disclosure
CVSS 4.3
CVE-2025-24604 MEDIUM
Vikas Ratudi VForm <3.0.5 - Info Disclosure
CVSS 5.4
CVE-2025-24596 MEDIUM
WooCommerce Product Table Lite <= 3.8.7 - Missing Authorization
CVSS 5.3
CVE-2025-24594 MEDIUM
Speedcomp Linet ERP-Woocommerce Integration <3.5.7 - Info Disclosure
CVSS 6.5
CVE-2025-24591 MEDIUM
Ninja Team GDPR CCPA Compliance Support <= 2.7.1 - Missing Authorization
CVSS 4.3
CVE-2025-24589 MEDIUM
JSM Show Post Metadata <4.6.0 - Info Disclosure
CVSS 4.3
CVE-2025-24588 MEDIUM
Patreon WordPress <1.9.1 - Info Disclosure
CVSS 6.5
CVE-2025-24580 MEDIUM
Code for Recovery <3.16.5 - Info Disclosure
CVSS 6.5
CVE-2025-24571 MEDIUM
Epsiloncool WP Fast Total Search <1.78.258 - Info Disclosure
CVSS 5.4
CVE-2025-22612 CRITICAL
Coolify < 4.0.0-beta.374 - Authenticated Private Key Exposure and Remote Command Execution
CVSS 10.0
CVE-2025-22611 CRITICAL
Coolify < 4.0.0-beta.361 - Authenticated Privilege Escalation and Remote Command Execution
CVSS 9.9
CVE-2025-22610 MEDIUM
Coolify < 4.0.0-beta.361 - Authenticated Missing Authorization for OAuth Configuration
CVSS 6.5
CVE-2025-22609 CRITICAL
Coolify < 4.0.0-beta.361 - Authenticated Private Key Attachment and Remote Command Execution
CVSS 10.0
CVE-2025-22608 MEDIUM
Coolify < 4.0.0-beta.361 - Authenticated Denial of Service via Team Invitation Revocation
CVSS 6.5
CVE-2025-23991 MEDIUM
Product Size Charts Plugin for WooCommerce <2.4.5 - Info Disclosure
CVSS 4.3
CVE-2025-22607 MEDIUM
Coolify < 4.0.0-beta.361 - Authenticated Information Disclosure via GitHub/GitLab Configuration UUID
CVSS 5.5
Details
Vulnerabilities 8,344
Exploit Likelihood High