The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,323 vulnerabilities with CWE-862
CVE-2025-12170
MEDIUM
Checkbox plugin <2.8.10 - Info Disclosure
CVSS 5.3
CVE-2025-11985
HIGH
Realty Portal <0.4.1 - Privilege Escalation
CVSS 8.8
CVE-2025-11773
MEDIUM
TokenICO plugin <2.4.6 - Info Disclosure
CVSS 4.3
CVE-2025-11003
MEDIUM
UiPress lite < 3.5.08 - Authenticated Arbitrary JavaScript Execution via Template Save
CVSS 6.4
CVE-2025-10938
MEDIUM
UiPress lite <3.5.08 - Info Disclosure
CVSS 6.5
CVE-2025-9825
MEDIUM
GitLab 13.7-18.2.8, 18.3-18.3.4, 18.4-18.4.2 - Authenticated Sensitive CI/CD Variable Exposure via GraphQL API
CVSS 5.0
CVE-2025-12169
MEDIUM
Elula Wsdesk < 3.3.1 - Missing Authorization
CVSS 4.3
CVE-2025-12085
MEDIUM
Elula Wsdesk < 3.3.2 - Missing Authorization
CVSS 4.3
CVE-2025-12023
MEDIUM
Elula Wsdesk < 3.3.2 - Missing Authorization
CVSS 4.3
CVE-2025-12022
MEDIUM
Elula Wsdesk < 3.3.2 - Missing Authorization
CVSS 4.3
CVE-2025-52670
MEDIUM
Revive Adserver < 5.5.2 - Authorization Bypass via Banner Deletion
CVSS 6.5
CVE-2025-62293
MEDIUM
soplanning < 1.55.00 - Authenticated Broken Access Control in Project Status Endpoint
CVSS 5.4
CVE-2025-13468
MEDIUM
SourceCodester Alumni Management System 1.0 - Missing Authorization in Delete Handler
CVSS 5.4
CVE-2025-12778
MEDIUM
Ultimate Member Widgets - Info Disclosure
CVSS 5.3
CVE-2025-65089
MEDIUM
XWiki Remote Macros < 1.27.0 - Missing Authorization in View File Macro
CVSS 6.8
CVE-2025-65029
HIGH
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference in Participant Deletion Endpoint
CVSS 8.1
CVE-2025-65028
MEDIUM
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via ParticipantId Parameter
CVSS 6.5
CVE-2025-65021
CRITICAL
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via Poll Finalization
CVSS 9.1
CVE-2025-65020
MEDIUM
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via Poll Duplication Endpoint
CVSS 6.5
CVE-2025-12822
MEDIUM
WP Login and Register using JWT <3.0.0 - Info Disclosure
CVSS 4.3
CVE-2025-12751
MEDIUM
WSChat - WordPress Live Chat <3.1.6 - Info Disclosure
CVSS 4.3
CVE-2025-12174
MEDIUM
Directorist: AI-Powered Business Directory Plugin <8.5.2 - Privileg...
CVSS 6.5
CVE-2025-12955
HIGH
WooCommerce <2.3.39 - Info Disclosure
CVSS 7.5
CVE-2025-12639
MEDIUM
wModes for WooCommerce <= 1.2.2 - Authenticated Authorization Bypass via AJAX Endpoint
CVSS 4.3
CVE-2025-12481
MEDIUM
WP Duplicate Page <1.7 - Auth Bypass
CVSS 4.3
Details
Vulnerabilities
8,323
Exploit Likelihood
High