CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,261 vulnerabilities with CWE-862
CVE-2026-22466 MEDIUM
WP MapIt <= 3.0.3 - Missing Authorization
CVSS 4.3
CVE-2026-22461 MEDIUM
WebAppick CTX Feed <= 6.6.18 - Missing Authorization
CVSS 5.3
CVE-2026-22458 MEDIUM
Mikado-Themes Wanderland - Info Disclosure
CVSS 4.3
CVE-2026-22450 MEDIUM
Select-Themes Don Peppe <= 1.3 - Missing Authorization
CVSS 4.3
CVE-2026-22447 MEDIUM
Select-Themes Prowess <= 1.8.1 - Info Disclosure
CVSS 5.3
CVE-2026-22445 MEDIUM
Proptech Plugin Apimo Connector <2.6.5 - RCE
CVSS 5.3
CVE-2026-22348 MEDIUM
Tasos Fel Civic Cookie Control <1.54 - RCE
CVSS 5.3
CVE-2026-24055 MEDIUM
langfuse < 3.147.0 - Unauthenticated Slack Integration Hijacking via ProjectId Spoofing
CVSS 5.3
CVE-2026-24042 CRITICAL
Appsmith < 1.94 - Unauthenticated Missing Authorization via View Mode Bypass
CVSS 9.4
CVE-2026-1036 MEDIUM
The Photo Gallery by 10Web - Mobile-Friendly Image Gallery <1.8.36 ...
CVSS 5.3
CVE-2026-23990 MEDIUM
Flux Operator <0.40.0 - Privilege Escalation
CVSS 5.3
CVE-2026-23517 HIGH
Fleet <4.78.3,4.77.1,4.76.2,4.75.2,4.53.3 - Info Disclosure
CVSS 8.1
CVE-2026-0554 MEDIUM
NotificationX <3.1.11 - Info Disclosure
CVSS 4.3
CVE-2026-0548 MEDIUM
Tutor LMS - WordPress Plugin <3.9.4 - Privilege Escalation
CVSS 5.4
CVE-2026-23875 MEDIUM
CrawlChat <0.0.8 - Privilege Escalation
CVSS 5.4
CVE-2026-23721 MEDIUM
OpenProject <17.0.1-16.6.5 - Info Disclosure
CVSS 4.3
CVE-2026-1169 MEDIUM
birkir prime < 0.4.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2026-23522 LOW
LobeChat <2.0.0-next.193 - Privilege Escalation
CVSS 3.7
CVE-2026-1153 MEDIUM
technical-laohu mpay < 1.2.4 - Cross-Site Request Forgery
CVSS 4.3
CVE-2026-1148 MEDIUM
Patients Waiting Area Queue Management System 1.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2026-1142 MEDIUM
PHPGurukul News Portal 1.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2026-0820 MEDIUM
RepairBuddy - Insecure Direct Object Reference
CVSS 4.3
CVE-2026-1004 MEDIUM
Essential Addons for Elementor <6.5.5 - Info Disclosure
CVSS 5.3
CVE-2026-1003 MEDIUM
GetGenie <= 4.3.0 - Authenticated Authorization Bypass via Post Deletion
CVSS 4.3
CVE-2026-1000 MEDIUM
MailerLite - WooCommerce <3.1.3 - Privilege Escalation
CVSS 6.5
Details
Vulnerabilities 8,261
Exploit Likelihood High