CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,324 vulnerabilities with CWE-862
CVE-2025-62028 MEDIUM
ThemeNectar Salient - Info Disclosure
CVSS 4.3
CVE-2025-62018 MEDIUM
Hogash Kallyas <4.22.0 - Info Disclosure
CVSS 5.3
CVE-2025-62017 MEDIUM
hogash Kallyas <4.22.0 - Info Disclosure
CVSS 5.4
CVE-2025-60247 MEDIUM
Bux Bux Woocommerce <1.2.4 - Info Disclosure
CVSS 6.5
CVE-2025-5803 MEDIUM
e4jvikwp VikBooking Hotel Booking Engine & PMS <1.8.3 - Info Disclo...
CVSS 5.3
CVE-2025-58986 MEDIUM
Ganddser JOAN <6.0.4 - Privilege Escalation
CVSS 6.5
CVE-2025-58629 HIGH
Miraculous < 2.0.9 - Info Disclosure
CVSS 7.5
CVE-2025-58243 MEDIUM
Jthemes imEvent <= 3.4.0 - Info Disclosure
CVSS 5.3
CVE-2025-58207 HIGH
WP Messiah Ai Image Alt Text Generator <1.1.5 - Info Disclosure
CVSS 8.2
CVE-2025-54711 HIGH
bPlugins Info Cards <= 1.0.11 - Missing Authorization
CVSS 7.1
CVE-2025-53246 MEDIUM
Gaurav Aggarwal Backup and Move <0.1 - Auth Bypass
CVSS 6.5
CVE-2025-53214 MEDIUM
Sertifier Certificate & Badge Maker <1.22 - RCE
CVSS 6.5
CVE-2025-49394 HIGH
bPlugins Image Gallery <1.0.8 - Info Disclosure
CVSS 7.1
CVE-2025-39465 MEDIUM
flippercode Advanced Google Maps <5.8.4 - Info Disclosure
CVSS 4.3
CVE-2025-12563 MEDIUM
Blog2Social <8.6.0 - Limited File Upload
CVSS 4.3
CVE-2025-64171 HIGH
marin3r <= 0.13.3 - Missing Authorization via DiscoveryServiceCertificate
CVE-2025-12469 MEDIUM
FunnelKit Automations < 3.6.4.1 - Authenticated Missing Authorization via bwfan_test_email AJAX Handler
CVSS 4.3
CVE-2025-12675 MEDIUM
KiotViet Sync <1.8.5 - Info Disclosure
CVSS 4.3
CVE-2025-12384 HIGH
Document Embedder <2.0.0 - Info Disclosure
CVSS 8.6
CVE-2025-11373 MEDIUM
Depicter Popup & Slider Builder <4.0.4 - RCE
CVSS 4.3
CVE-2025-11835 MEDIUM
Paid Membership Subscriptions <2.16.4 - Info Disclosure
CVSS 5.3
CVE-2025-12582 MEDIUM
WordPress Features <0.0.3 - Info Disclosure
CVSS 4.3
CVE-2025-63294 MEDIUM
WorkDo HRM <8.1 - Privilege Escalation
CVSS 6.5
CVE-2025-41345 HIGH
canaldenuncia.app < 4.4.8 - Missing Authorization via id_denuncia and id_user Parameters
CVSS 7.5
CVE-2025-41344 HIGH
canaldenuncia.app < 4.4.8 - Unauthenticated Information Disclosure via id_archivo Parameter
CVSS 7.5
Details
Vulnerabilities 8,324
Exploit Likelihood High