The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,230 vulnerabilities with CWE-862
CVE-2026-24967
MEDIUM
Amelia <= 1.2.38 - Missing Authorization
CVSS 5.3
CVE-2026-24965
MEDIUM
Contest Gallery <28.1.1 - Info Disclosure
CVSS 4.3
CVE-2026-24957
MEDIUM
WP Chill Strong Testimonials <3.2.20 - Info Disclosure
CVSS 6.5
CVE-2026-24951
MEDIUM
myCred <= 2.9.7.3 - Missing Authorization
CVSS 4.3
CVE-2026-24947
MEDIUM
LA-Studio Element Kit - Info Disclosure
CVSS 4.3
CVE-2026-24945
MEDIUM
Themefic Ultimate Addons for Contact Form 7 <3.5.34 - RCE
CVSS 5.3
CVE-2026-24940
MEDIUM
Travelfic Toolkit <= 1.3.3 - Missing Authorization
CVSS 4.3
CVE-2026-24939
MEDIUM
WP Chill Modula Image Gallery <2.13.7 - Info Disclosure
CVSS 4.3
CVE-2026-1751
LOW
GitLab CE/EE <18.5.0 - Info Disclosure
CVSS 3.1
CVE-2026-1745
MEDIUM
SourceCodester Medical Certificate Generator App 1.0 - CSRF
CVSS 4.3
CVE-2026-1734
MEDIUM
crmeb < 5.6.3 - Unauthenticated Incorrect Authorization in Crontab Endpoint
CVSS 5.3
CVE-2026-1431
MEDIUM
Booking Calendar <10.14.13 - Info Disclosure
CVSS 5.3
CVE-2026-21865
MEDIUM
Discourse < 3.5.4 - Missing Authorization for Personal Message Conversion
CVSS 6.5
CVE-2026-1280
HIGH
Frontend File Manager Plugin <23.5 - Info Disclosure
CVSS 7.5
CVE-2026-1054
MEDIUM
RegistrationMagic <6.0.7.4 - Auth Bypass
CVSS 5.3
CVE-2026-1310
MEDIUM
Simple Calendar for Elementor <1.6.6 - Auth Bypass
CVSS 5.3
CVE-2026-0832
HIGH
New User Approve <= 3.2.2 - Unauthenticated Data Access and Modification via REST API Endpoints
CVSS 7.3
CVE-2026-0825
MEDIUM
Database for Contact Form 7, WPforms, Elementor forms plugin - Auth...
CVSS 5.3
CVE-2026-1298
MEDIUM
WordPress Easy Replace Image <3.5.2 - Auth Bypass
CVSS 4.3
CVE-2026-24134
MEDIUM
StudioCMS <0.2.0 - Privilege Escalation
CVSS 6.5
CVE-2026-23683
MEDIUM
SAP Fiori App Intercompany Balance Reconciliation - Privilege Escal...
CVSS 4.3
CVE-2026-0593
MEDIUM
WP Go Maps <10.0.04 - Info Disclosure
CVSS 5.3
CVE-2026-0687
MEDIUM
Meta-box GalleryMeta <3.0.1 - Info Disclosure
CVSS 4.3
CVE-2026-1103
MEDIUM
AIKTP WordPress <5.0.04 - Info Disclosure
CVSS 5.4
CVE-2026-24421
MEDIUM
phpmyfaq < 4.0.17 - Authenticated Missing Authorization in Setup Backup Endpoint
CVSS 6.5
Details
Vulnerabilities
8,230
Exploit Likelihood
High