CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,213 vulnerabilities with CWE-862
CVE-2026-30850 MEDIUM
Parse Server <8.6.9/9.5.0-alpha.9 - Auth Bypass
CVSS 5.9
CVE-2026-30842 MEDIUM
Wallos <4.6.2 - Privilege Escalation
CVSS 4.3
CVE-2026-30823 HIGH
Flowise < 3.0.13 - Unauthenticated IDOR and Account Takeover via SSO Configuration
CVSS 8.8
CVE-2026-27796 MEDIUM
homarr < 1.54.0 - Unauthenticated Sensitive Information Exposure via tRPC Integration Endpoint
CVSS 5.3
CVE-2026-2488 MEDIUM
ProfileGrid WordPress Plugin <=5.9.8.1 - Auth Bypass
CVSS 4.3
CVE-2026-1650 MEDIUM
MDJM Event Management Plugin <1.7.8.1 - Auth Bypass
CVSS 5.3
CVE-2026-2371 MEDIUM
Greenshift Plugin <12.8.3 - Insecure Direct Object Reference
CVSS 5.3
CVE-2026-1981 MEDIUM
HUMN-1 AI Website Scanner 0.0.3 - Auth Bypass
CVSS 4.3
CVE-2026-30233 MEDIUM
olivetin < 3000.11.1 - Authenticated Information Disclosure via Dashboard and API Endpoints
CVSS 6.5
CVE-2026-29789 CRITICAL
Vito <3.20.3 - Privilege Escalation
CVSS 9.9
CVE-2026-30845 HIGH
Wekan 8.31.0-8.33 - Info Disclosure
CVSS 8.2
CVE-2026-28080 MEDIUM
Rank Math SEO PRO <3.0.95 - Privilege Escalation
CVSS 4.3
CVE-2026-29073 HIGH
SiYuan < 3.6.0 - Authenticated SQL Injection via /api/query/sql
CVSS 8.8
CVE-2026-2446 CRITICAL
PowerPack for LearnDash <1.3.0 - Privilege Escalation
CVSS 9.8
CVE-2026-28790 HIGH
olivetin < 3000.11.0 - Unauthenticated Denial of Service via KillAction RPC
CVSS 7.5
CVE-2026-30797 HIGH
RustDesk Client <=1.4.5 - Auth Bypass
CVSS 8.1
CVE-2026-30784 CRITICAL
RustDesk Server - Privilege Escalation
CVSS 9.8
CVE-2026-1720 HIGH
WowOptin Popup Maker <=1.4.24 - Auth Bypass
CVSS 8.8
CVE-2026-1321 HIGH
Membership Plugin - Restrict Content <3.2.20 - Privilege Escalation
CVSS 8.1
CVE-2026-3072 MEDIUM
Media Library Assistant <=3.33 - Privilege Escalation
CVSS 4.3
CVE-2026-28104 MEDIUM
Site Suggest <= 1.3.9 - Missing Authorization
CVSS 6.5
CVE-2026-28076 HIGH
Frenify Guff <= 1.0.1 - Missing Authorization
CVSS 7.5
CVE-2026-28071 MEDIUM
PixFort pixfort Core <=3.2.22 - Auth Bypass
CVSS 6.3
CVE-2026-28038 MEDIUM
Ultimate Addons for WPBakery Page Builder <=3.21.1 - Auth Bypass
CVSS 6.5
CVE-2026-27396 HIGH
Directory Pro <=2.5.6 - Auth Bypass
CVSS 7.3
Details
Vulnerabilities 8,213
Exploit Likelihood High