The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,807 vulnerabilities with CWE-862
CVE-2026-53647
MEDIUM
FOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint
CVE-2026-53643
HIGH
FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints
CVE-2026-53640
LOW
FOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect data
CVE-2026-34050
MEDIUM
Coolify Settings/Updates Livewire component missing instance administrator authorization
CVSS 6.5
CVE-2026-14800
MEDIUM
imhamzaazam ecommerceFlask cross-site request forgery
CVSS 4.3
CVE-2026-6509
HIGH
Privilege Escalation in TUBITAK BILGEM's Pardus Update
CVSS 7.8
CVE-2026-27783
MEDIUM
Gitea issue-template APIs bypass repository unit authorization
CVSS 4.3
CVE-2026-27771
HIGH
Gitea Composer package source links use insufficient permission checks
CVSS 8.2
CVE-2026-25714
MEDIUM
Gitea user organization API bypasses public-only token filtering
CVSS 4.3
CVE-2026-25038
HIGH
Gitea private organization labels are visible to unauthorized users
CVSS 7.5
CVE-2026-14460
HIGH
Missing Authorization in TUBITAK BILGEM's pardus-software
CVSS 8.8
CVE-2026-11398
MEDIUM
LatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step
CVSS 5.3
CVE-2026-9230
MEDIUM
Quiz And Survey Master (qsm) – Easy Quiz And Survey Maker < 11.1.4 - Authorization Bypass
CVSS 4.3
CVE-2026-12557
MEDIUM
Ninja Forms - File Uploads < 3.3.29 - Authorization Bypass
CVSS 5.3
CVE-2026-12729
MEDIUM
weDevs weDocs <= 2.3.0 - Subscriber+ Missing Authorization in Data Migration
CVSS 4.3
CVE-2026-59097
MEDIUM
Taiga < 6.10.2 - Unauthorized Due-Date Creation via API Viewsets
CVSS 5.3
CVE-2026-50282
MEDIUM
Craft CMS: Unauthorized Deletion of Destination Folders During Forced Moves
CVE-2026-57760
MEDIUM
WordPress Sendcloud Shipping plugin <= 1.0.29 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57750
MEDIUM
WordPress ez Form Calculator Premium plugin <= 2.14.1.2 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57746
HIGH
WordPress Booked plugin <= 3.0.0 - Broken Access Control vulnerability
CVSS 7.1
CVE-2026-57731
MEDIUM
WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57730
MEDIUM
WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-57689
MEDIUM
WordPress Werkstatt theme <= 4.7.2 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-57688
HIGH
WordPress POS Entegratör plugin <= 3.7.103 - Broken Access Control vulnerability
CVSS 8.2
CVE-2026-57685
MEDIUM
WordPress Martfury - WooCommerce Marketplace WordPress theme theme <= 3.2.8 - Broken Access Control vulnerability
CVSS 4.3
Details
Vulnerabilities
8,807
Exploit Likelihood
High