The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,808 vulnerabilities with CWE-862
CVE-2026-9233
MEDIUM
Quiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action
CVSS 4.3
CVE-2026-3462
MEDIUM
Frisbii Pay <= 1.8.9 - Missing Authorization to Authenticated (Subscriber+) Payment Token Modification
CVSS 6.5
CVE-2026-12471
MEDIUM
Spexo <= 2.0.11 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activation
CVSS 4.3
CVE-2026-12432
MEDIUM
Stripe Payment Forms by WP Full Pay <= 8.4.3 - Missing Authorization to Unauthenticated Payment Record Manipulation via 'paymentIntentId' Parameter
CVSS 5.3
CVE-2026-11773
MEDIUM
Masteriyo LMS <= 2.2.1 - Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement Modification
CVSS 4.3
CVE-2026-11364
MEDIUM
Product Specifications for WooCommerce <= 0.8.9 - Missing Authorization
CVSS 4.3
CVE-2026-12404
MEDIUM
NEX-Forms <= 9.2.2 - Unauthenticated Form Submission Data Disclosure
CVSS 5.3
CVE-2026-50137
CRITICAL
Budibase < 3.39.0 - Unauthenticated S3 Presigned Upload URL Creation
CVSS 9.4
CVE-2026-55838
MEDIUM
RustFS Metrics API - Authorization Bypass
CVSS 4.3
CVE-2026-55189
HIGH
RustFS: FTP frontend skips IAM authorization on object reads
CVSS 7.7
CVE-2026-55188
HIGH
RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials
CVSS 8.2
CVE-2026-49991
HIGH
RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injection
CVSS 8.6
CVE-2026-47193
HIGH
OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checks
CVSS 7.5
CVE-2026-44734
MEDIUM
OpenProject: Improper Access Control on OpenProject through the POST request to /projects/[PROJECT_NAME]/cost_reports/[REPORT_ID]/rename
CVSS 6.5
CVE-2026-57518
HIGH
Pagekit CMS 1.0.18 Privilege Escalation via UserApiController
CVSS 8.8
CVE-2026-12411
HIGH
Broken Access Control in Canonical LXD DevLXD API
CVSS 8.4
CVE-2026-57661
MEDIUM
WordPress WPComplete plugin <= 2.9.5.5 - Broken Access Control vulnerability
CVSS 5.4
CVE-2026-57660
MEDIUM
WordPress Booking and Rental Manager plugin <= 2.7.1 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-57654
MEDIUM
WordPress Affiliates Manager plugin <= 2.9.49 - Broken Access Control vulnerability
CVSS 6.5
CVE-2026-57649
MEDIUM
WordPress Shoppable Images Lite plugin <= 1.3 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-57648
MEDIUM
WordPress Nelio Content plugin <= 4.3.4 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-57645
HIGH
WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability
CVSS 8.1
CVE-2026-57640
MEDIUM
WordPress MasterStudy LMS plugin <= 3.7.30 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-57632
MEDIUM
WordPress Email Marketing for WooCommerce by Omnisend plugin <= 1.19.0 - Broken Access Control vulnerability
CVSS 5.4
CVE-2026-57622
MEDIUM
WordPress WPCafe plugin <= 3.0.14 - Broken Access Control vulnerability
CVSS 4.3
Details
Vulnerabilities
8,808
Exploit Likelihood
High