CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,281 vulnerabilities with CWE-862
CVE-2025-14397 HIGH
Postem Ipsum <3.0.1 - Privilege Escalation
CVSS 8.8
CVE-2025-14395 MEDIUM
Popover Windows <1.3 - Info Disclosure
CVSS 4.3
CVE-2025-14367 MEDIUM
Easy Theme Options <1.0 - Auth Bypass
CVSS 5.3
CVE-2025-14366 MEDIUM
Eyewear prescription form plugin <6.0.1 - Auth Bypass
CVSS 5.3
CVE-2025-14365 MEDIUM
Eyewear plugin <6.0.1 - Auth Bypass
CVSS 5.3
CVE-2025-14288 MEDIUM
WordPress Gallery Blocks <3.3.0 - Privilege Escalation
CVSS 4.3
CVE-2025-13403 MEDIUM
Employee Spotlight <5.1.3 - Privilege Escalation
CVSS 4.3
CVE-2025-13093 MEDIUM
Devs CRM < 1.1.8 - Unauthenticated Data Modification via Bulk Update REST-API Endpoint
CVSS 5.3
CVE-2025-13092 MEDIUM
Devs CRM < 1.1.8 - Unauthenticated Sensitive Data Exposure via REST API Endpoint
CVSS 5.3
CVE-2025-12362 MEDIUM
myCred <= 2.9.7 - Unauthenticated Missing Authorization via cashcred_pay_now
CVSS 5.3
CVE-2025-11164 MEDIUM
Mavix Education <1.0 - Privilege Escalation
CVSS 4.3
CVE-2025-43497 MEDIUM
macOS Tahoe <26.1 - Info Disclosure
CVSS 5.2
CVE-2025-14065 MEDIUM
Simple Bike Rental <1.0.6 - Info Disclosure
CVSS 4.3
CVE-2025-14074 MEDIUM
Contact Form 7 + Drag and Drop Template Builder <6.3.3 - Info Discl...
CVSS 4.3
CVE-2025-10583 LOW
WP Fastest Cache Premium <= 1.7.4 - Authenticated Server-Side Request Forgery via get_server_time_ajax_request
CVSS 3.5
CVE-2025-67737 LOW
AzuraCast < 0.23.2 - Missing Authorization in SFTP API Endpoint
CVSS 3.1
CVE-2025-12655 MEDIUM
Hippoo Mobile App <1.7.1 - Code Injection
CVSS 5.3
CVE-2025-14392 MEDIUM
Simple Theme Changer <1.0 - Info Disclosure
CVSS 4.3
CVE-2025-14170 MEDIUM
Vimeo SimpleGallery <0.2 - Auth Bypass
CVSS 4.3
CVE-2025-14064 MEDIUM
BuddyTask <1.3.0 - Privilege Escalation
CVSS 5.4
CVE-2025-14045 MEDIUM
URL Media Uploader <1.0.1 - Auth Bypass
CVSS 4.3
CVE-2025-13866 MEDIUM
Flow-Flow Social Feed Stream <4.7.5 - Info Disclosure
CVSS 6.4
CVE-2025-13440 MEDIUM
Premmerce Wishlist <1.1.10 - Auth Bypass
CVSS 5.3
CVE-2025-13334 HIGH
Blaze Demo Importer <1.0.13 - Privilege Escalation
CVSS 8.1
CVE-2025-13314 MEDIUM
WooCommerce Filter Plus <1.1.5 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 8,281
Exploit Likelihood High