The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,272 vulnerabilities with CWE-862
CVE-2025-13859
MEDIUM
WordPress AffiliateX - Info Disclosure
CVSS 6.4
CVE-2025-12895
MEDIUM
Kalium 3 | Creative WordPress & WooCommerce Theme <3.29 - Info Disc...
CVSS 5.3
CVE-2025-14457
LOW
Contact Form 7 <1.3.9.2 - Info Disclosure
CVSS 3.7
CVE-2025-15512
MEDIUM
Aplazo Payment Gateway <1.4.2 - Info Disclosure
CVSS 5.3
CVE-2025-15475
MEDIUM
PayHere Payment Gateway Plugin <2.3.9 - Info Disclosure
CVSS 5.3
CVE-2025-14173
MEDIUM
Perfit WooCommerce <1.0.1 - Auth Bypass
CVSS 5.3
CVE-2025-14880
MEDIUM
Netchash WooCommerce Payment Gateway <4.1.3 - Info Disclosure
CVSS 5.3
CVE-2025-14854
MEDIUM
WP-CRM System <3.4.5 - Info Disclosure
CVSS 5.4
CVE-2025-14482
MEDIUM
Crush.pics Image Optimizer <1.8.7 - Info Disclosure
CVSS 4.3
CVE-2025-68947
MEDIUM
NSecsoft 'NSecKrnl' - Privilege Escalation
CVSS 4.7
CVE-2025-11669
HIGH
ManageEngine PAM360 < 8.2, Password Manager Pro < 13.2, Access Manager Plus < 4.4 - Missing Authorization
CVSS 8.1
CVE-2025-59022
HIGH
Typo3 < 10.4.55 - Missing Authorization
CVSS 8.1
CVE-2025-59021
MEDIUM
Typo3 < 10.4.55 - Missing Authorization
CVSS 6.4
CVE-2025-14001
MEDIUM
WP Duplicate Page <1.9 - Info Disclosure
CVSS 5.4
CVE-2025-14948
MEDIUM
miniOrange OTP Verification - Info Disclosure
CVSS 5.3
CVE-2025-14172
MEDIUM
WP Page Permalink Extension <1.5.4 - Auth Bypass
CVSS 6.5
CVE-2025-13717
MEDIUM
Contact Form vCard Generator <2.4 - Info Disclosure
CVSS 5.3
CVE-2025-13781
MEDIUM
GitLab 18.5-18.5.4, 18.6-18.6.2, 18.7-18.7.0 - Authenticated Missing Authorization in GraphQL Mutations
CVSS 6.5
CVE-2025-13772
HIGH
GitLab 18.4.0-18.5.4, 18.6.0-18.6.2, 18.7.0 - Authenticated Missing Authorization via Namespace Identifier Manipulation
CVSS 7.1
CVE-2025-14741
CRITICAL
Frontend Admin by DynamiApps - Auth Bypass
CVSS 9.1
CVE-2025-14657
HIGH
Eventin - Event Manager - Info Disclosure
CVSS 7.2
CVE-2025-14146
MEDIUM
Booking Calendar <10.14.10 - Info Disclosure
CVSS 5.3
CVE-2025-13935
MEDIUM
Tutor LMS - WordPress <3.9.2 - Privilege Escalation
CVSS 4.3
CVE-2025-13934
MEDIUM
Tutor LMS - WordPress <3.9.3 - Privilege Escalation
CVSS 4.3
CVE-2025-13628
MEDIUM
Tutor LMS - WordPress <3.9.3 - Privilege Escalation
CVSS 4.3
Details
Vulnerabilities
8,272
Exploit Likelihood
High