The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,261 vulnerabilities with CWE-862
CVE-2025-70141
CRITICAL
SourceCodester Customer Support System 1.0 - Auth Bypass
CVSS 9.4
CVE-2025-12356
MEDIUM
Tickera WordPress Plugin <3.5.6.4 - Privilege Escalation
CVSS 4.3
CVE-2025-12075
MEDIUM
Order Splitter for WooCommerce <=5.3.5 - Info Disclosure
CVSS 4.3
CVE-2025-14573
LOW
Mattermost <10.11.10 - Privilege Escalation
CVSS 3.8
CVE-2025-14350
MEDIUM
Mattermost <11.1.2, 10.11.9, 11.2.1 - Info Disclosure
CVSS 4.3
CVE-2025-14608
MEDIUM
WP Last Modified Info <1.9.5 - Info Disclosure
CVSS 5.3
CVE-2025-14067
MEDIUM
Easy Form Builder <3.9.3 - Info Disclosure
CVSS 5.3
CVE-2025-15157
HIGH
Starfish Review Generation & Marketing <3.1.19 - Privilege Escalation
CVSS 8.8
CVE-2025-13391
MEDIUM
WooCommerce Uni CPO <4.9.60 - Info Disclosure
CVSS 5.8
CVE-2025-14592
LOW
GitLab CE/EE <18.6.6-18.8.4 - Privilege Escalation
CVSS 3.7
CVE-2025-15400
MEDIUM
Pix para Woocommerce <2.13.3 - Privilege Escalation
CVSS 6.5
CVE-2025-15524
MEDIUM
The Gallery by FooGallery plugin <3.1.9 - Info Disclosure
CVSS 4.3
CVE-2025-14895
MEDIUM
Popup Builder <= 2.2.0 - Authenticated Authorization Bypass via REST API
CVSS 5.4
CVE-2025-15476
MEDIUM
The Bucketlister plugin <0.1.5 - Info Disclosure
CVSS 4.3
CVE-2025-10753
MEDIUM
OAuth Single Sign On - SSO (OAuth Client) <= 6.26.14 - Unauthenticated Arbitrary Redirect via oauthredirect Parameter
CVSS 5.3
CVE-2025-15330
HIGH
Tanium Deploy 2.26.0-2.26.1279 - Missing Authorization
CVSS 8.8
CVE-2025-15327
MEDIUM
Tanium Deploy 2.26.0-2.26.1252 - Missing Authorization
CVSS 4.3
CVE-2025-15326
MEDIUM
Tanium Patch 3.17.0-3.17.2261 - Missing Authorization
CVSS 4.3
CVE-2025-15289
LOW
Tanium Interact 3.1.0-3.1.336 - Missing Authorization
CVSS 3.1
CVE-2025-14079
MEDIUM
ELEX WordPress HelpDesk & Customer Ticketing System <3.3.5 - Auth B...
CVSS 5.3
CVE-2025-13416
MEDIUM
ProfileGrid - User Profiles, Groups and Communities <5.9.7.2 - Priv...
CVSS 4.3
CVE-2025-15507
MEDIUM
Magic Import Document Extractor <1.0.4 - Info Disclosure
CVSS 5.3
CVE-2025-15285
HIGH
SEO Flow by LupsOnline <2.2.1 - Info Disclosure
CVSS 7.5
CVE-2025-15260
MEDIUM
MyRewards for WooCommerce - Missing Authorization in Ajax Function
CVSS 6.5
CVE-2025-14461
MEDIUM
Xendit Payment <6.0.2 - Auth Bypass
CVSS 5.3
Details
Vulnerabilities
8,261
Exploit Likelihood
High