The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,324 vulnerabilities with CWE-862
CVE-2025-11833
CRITICAL
Post SMTP < 3.6.0 - Unauthenticated Arbitrary Email Log Access via Missing Capability Check
CVSS 9.8
CVE-2025-11816
MEDIUM
WP Legal Pages <3.5.1 - Info Disclosure
CVSS 5.3
CVE-2025-64349
HIGH
elog < 3.1.5-20251014 - Authenticated Account Takeover via Profile Modification
CVSS 8.8
CVE-2025-64348
HIGH
elog < 3.1.5-20251014 - Authenticated Configuration File Overwrite and Denial of Service
CVSS 7.1
CVE-2025-64358
MEDIUM
WebToffee Smart Coupons <2.2.3 - RCE
CVSS 4.3
CVE-2025-64356
MEDIUM
Insert PHP Code Snippet <1.4.3 - RCE
CVSS 4.3
CVE-2025-64352
LOW
WPDeveloper Essential Addons for Elementor <= 6.2.4 - Missing Authorization
CVSS 2.7
CVE-2025-64350
LOW
Rank Math SEO <= 1.0.252.1 - Missing Authorization
CVSS 3.8
CVE-2025-12041
MEDIUM
ERI File Library plugin <1.1.0 - Info Disclosure
CVSS 5.3
CVE-2025-12175
MEDIUM
The Events Calendar <6.15.9 - Auth Bypass
CVSS 4.3
CVE-2025-11191
MEDIUM
RealPress <1.1.0 - Privilege Escalation
CVSS 5.3
CVE-2025-11975
MEDIUM
FuseWP < 1.1.23.0 - Unauthenticated Data Modification
CVSS 4.3
CVE-2025-62712
CRITICAL
JumpServer < 3.10.20 - Authenticated Missing Authorization via Super-Connection API Endpoint
CVSS 9.6
CVE-2025-11881
MEDIUM
AppPresser - Mobile App Framework <= 4.5.0 - Unauthenticated Sensitive Data Exposure via myappp_verify Function
CVSS 5.3
CVE-2025-10008
MEDIUM
Translate Weglot <5.1 - Info Disclosure
CVSS 5.3
CVE-2025-9954
HIGH
Acquia DAM < 1.1.5 - Missing Authorization
CVSS 7.5
CVE-2025-64150
MEDIUM
Jenkins Publish to Bitbucket Plugin < 0.4 - Missing Authorization for Credential Capture via URL Connection
CVSS 5.4
CVE-2025-64148
MEDIUM
Jenkins Publish to Bitbucket Plugin < 0.4 - Missing Authorization for Credential ID Enumeration
CVSS 4.3
CVE-2025-64142
MEDIUM
Jenkins Nexus Task Runner Plugin <= 0.9.2 - Missing Authorization for URL Connection
CVSS 4.3
CVE-2025-64139
MEDIUM
Jenkins Start Windocks Containers Plugin < 1.4 - Missing Authorization
CVSS 4.3
CVE-2025-64137
MEDIUM
Jenkins Themis < 1.4.1 - Server-Side Request Forgery via Missing Permission Check
CVSS 4.3
CVE-2025-64132
MEDIUM
Jenkins MCP Server Plugin < 0.84.v50ca_24ef83f2 - Missing Authorization in MCP Tools
CVSS 5.4
CVE-2025-11632
MEDIUM
The Call Now Button - Unauthorized Access
CVSS 4.3
CVE-2025-11587
MEDIUM
The Call Now Button - The #1 Click to Call Button for WordPress <1....
CVSS 4.3
CVE-2025-64285
MEDIUM
Premmerce Wholesale Pricing <1.1.11 - RCE
CVSS 5.4
Details
Vulnerabilities
8,324
Exploit Likelihood
High