CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,323 vulnerabilities with CWE-862
CVE-2025-12170 MEDIUM
Checkbox plugin <2.8.10 - Info Disclosure
CVSS 5.3
CVE-2025-11985 HIGH
Realty Portal <0.4.1 - Privilege Escalation
CVSS 8.8
CVE-2025-11773 MEDIUM
TokenICO plugin <2.4.6 - Info Disclosure
CVSS 4.3
CVE-2025-11003 MEDIUM
UiPress lite < 3.5.08 - Authenticated Arbitrary JavaScript Execution via Template Save
CVSS 6.4
CVE-2025-10938 MEDIUM
UiPress lite <3.5.08 - Info Disclosure
CVSS 6.5
CVE-2025-9825 MEDIUM
GitLab 13.7-18.2.8, 18.3-18.3.4, 18.4-18.4.2 - Authenticated Sensitive CI/CD Variable Exposure via GraphQL API
CVSS 5.0
CVE-2025-12169 MEDIUM
Elula Wsdesk < 3.3.1 - Missing Authorization
CVSS 4.3
CVE-2025-12085 MEDIUM
Elula Wsdesk < 3.3.2 - Missing Authorization
CVSS 4.3
CVE-2025-12023 MEDIUM
Elula Wsdesk < 3.3.2 - Missing Authorization
CVSS 4.3
CVE-2025-12022 MEDIUM
Elula Wsdesk < 3.3.2 - Missing Authorization
CVSS 4.3
CVE-2025-52670 MEDIUM
Revive Adserver < 5.5.2 - Authorization Bypass via Banner Deletion
CVSS 6.5
CVE-2025-62293 MEDIUM
soplanning < 1.55.00 - Authenticated Broken Access Control in Project Status Endpoint
CVSS 5.4
CVE-2025-13468 MEDIUM
SourceCodester Alumni Management System 1.0 - Missing Authorization in Delete Handler
CVSS 5.4
CVE-2025-12778 MEDIUM
Ultimate Member Widgets - Info Disclosure
CVSS 5.3
CVE-2025-65089 MEDIUM
XWiki Remote Macros < 1.27.0 - Missing Authorization in View File Macro
CVSS 6.8
CVE-2025-65029 HIGH
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference in Participant Deletion Endpoint
CVSS 8.1
CVE-2025-65028 MEDIUM
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via ParticipantId Parameter
CVSS 6.5
CVE-2025-65021 CRITICAL
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via Poll Finalization
CVSS 9.1
CVE-2025-65020 MEDIUM
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via Poll Duplication Endpoint
CVSS 6.5
CVE-2025-12822 MEDIUM
WP Login and Register using JWT <3.0.0 - Info Disclosure
CVSS 4.3
CVE-2025-12751 MEDIUM
WSChat - WordPress Live Chat <3.1.6 - Info Disclosure
CVSS 4.3
CVE-2025-12174 MEDIUM
Directorist: AI-Powered Business Directory Plugin <8.5.2 - Privileg...
CVSS 6.5
CVE-2025-12955 HIGH
WooCommerce <2.3.39 - Info Disclosure
CVSS 7.5
CVE-2025-12639 MEDIUM
wModes for WooCommerce <= 1.2.2 - Authenticated Authorization Bypass via AJAX Endpoint
CVSS 4.3
CVE-2025-12481 MEDIUM
WP Duplicate Page <1.7 - Auth Bypass
CVSS 4.3
Details
Vulnerabilities 8,323
Exploit Likelihood High