The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,316 vulnerabilities with CWE-862
CVE-2025-48575
HIGH
CertInstaller - Privilege Escalation
CVSS 7.8
CVE-2025-32319
MEDIUM
Android - Missing Authorization in RemotePrintService
CVSS 6.7
CVE-2025-14117
MEDIUM
fit2cloud Halo 2.21.10 - Cross-Site Request Forgery
CVSS 4.3
CVE-2025-13666
MEDIUM
Helloprint < 2.1.2 - Unauthenticated Missing Authorization via REST API Endpoint
CVSS 5.3
CVE-2025-13358
MEDIUM
WordPress Accessibility Plugin <1.0.0 - Privilege Escalation
CVSS 5.3
CVE-2025-13309
MEDIUM
CodeConfig Accessibility < 1.0.2 - Authenticated Authorization Bypass via Settings Modification
CVSS 4.3
CVE-2025-12721
MEDIUM
g-FFL Cockpit plugin <1.7.2 - Info Disclosure
CVSS 5.3
CVE-2025-12577
MEDIUM
Listar - Directory Listing & Classifieds WordPress Plugin <3.0.0 - ...
CVSS 4.3
CVE-2025-12574
MEDIUM
Listar - Directory Listing & Classifieds WordPress Plugin <= 3.0.0 - Unauthorized Data Deletion via REST API Endpoint
CVSS 4.3
CVE-2025-12091
MEDIUM
Search, Filters & Merchandising for WooCommerce <3.0.63 - Info Disc...
CVSS 4.3
CVE-2025-65036
HIGH
XWiki Remote Macros < 1.27.1 - Remote Code Execution via Unauthorized Velocity Execution
CVSS 8.3
CVE-2025-13620
MEDIUM
Wp Social Login & Register Social Counter <3.1.3 - Auth Bypass
CVSS 5.3
CVE-2025-12876
MEDIUM
Projectopia - WordPress Project Management <5.1.19 - Info Disclosure
CVSS 5.3
CVE-2025-12355
MEDIUM
Payaza plugin <0.3.8 - Info Disclosure
CVSS 5.3
CVE-2025-12354
MEDIUM
Live CSS Preview <2.0.0 - Info Disclosure
CVSS 4.3
CVE-2025-12093
MEDIUM
Voidek Employee Portal <1.0.6 - Auth Bypass
CVSS 5.3
CVE-2025-13528
MEDIUM
WordPress Feedback Modal <1.0.1 - Info Disclosure
CVSS 5.3
CVE-2025-12370
MEDIUM
Takeads WordPress <1.0.13 - Auth Bypass
CVSS 4.3
CVE-2025-12165
MEDIUM
Webcake - Landing Page Builder <1.1 - Info Disclosure
CVSS 4.3
CVE-2025-12133
MEDIUM
EPROLO Dropshipping <2.3.1 - Info Disclosure
CVSS 4.3
CVE-2025-13313
CRITICAL
CRM Memberships <2.5 - Privilege Escalation
CVSS 9.8
CVE-2025-13312
MEDIUM
WordPress CRM Memberships <2.5 - Info Disclosure
CVSS 5.3
CVE-2025-54159
HIGH
Synology BeeDrive < 1.4.2-13960 - Unauthenticated Arbitrary File Deletion
CVSS 7.5
CVE-2025-2848
MEDIUM
Synology Mail Server < 1.7.6-10676 - Authenticated Missing Authorization
CVSS 6.3
CVE-2025-12826
MEDIUM
Custom Post Type UI <1.18.0 - Auth Bypass
CVSS 4.8
Details
Vulnerabilities
8,316
Exploit Likelihood
High