CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,324 vulnerabilities with CWE-862
CVE-2025-11833 CRITICAL
Post SMTP < 3.6.0 - Unauthenticated Arbitrary Email Log Access via Missing Capability Check
CVSS 9.8
CVE-2025-11816 MEDIUM
WP Legal Pages <3.5.1 - Info Disclosure
CVSS 5.3
CVE-2025-64349 HIGH
elog < 3.1.5-20251014 - Authenticated Account Takeover via Profile Modification
CVSS 8.8
CVE-2025-64348 HIGH
elog < 3.1.5-20251014 - Authenticated Configuration File Overwrite and Denial of Service
CVSS 7.1
CVE-2025-64358 MEDIUM
WebToffee Smart Coupons <2.2.3 - RCE
CVSS 4.3
CVE-2025-64356 MEDIUM
Insert PHP Code Snippet <1.4.3 - RCE
CVSS 4.3
CVE-2025-64352 LOW
WPDeveloper Essential Addons for Elementor <= 6.2.4 - Missing Authorization
CVSS 2.7
CVE-2025-64350 LOW
Rank Math SEO <= 1.0.252.1 - Missing Authorization
CVSS 3.8
CVE-2025-12041 MEDIUM
ERI File Library plugin <1.1.0 - Info Disclosure
CVSS 5.3
CVE-2025-12175 MEDIUM
The Events Calendar <6.15.9 - Auth Bypass
CVSS 4.3
CVE-2025-11191 MEDIUM
RealPress <1.1.0 - Privilege Escalation
CVSS 5.3
CVE-2025-11975 MEDIUM
FuseWP < 1.1.23.0 - Unauthenticated Data Modification
CVSS 4.3
CVE-2025-62712 CRITICAL
JumpServer < 3.10.20 - Authenticated Missing Authorization via Super-Connection API Endpoint
CVSS 9.6
CVE-2025-11881 MEDIUM
AppPresser - Mobile App Framework <= 4.5.0 - Unauthenticated Sensitive Data Exposure via myappp_verify Function
CVSS 5.3
CVE-2025-10008 MEDIUM
Translate Weglot <5.1 - Info Disclosure
CVSS 5.3
CVE-2025-9954 HIGH
Acquia DAM < 1.1.5 - Missing Authorization
CVSS 7.5
CVE-2025-64150 MEDIUM
Jenkins Publish to Bitbucket Plugin < 0.4 - Missing Authorization for Credential Capture via URL Connection
CVSS 5.4
CVE-2025-64148 MEDIUM
Jenkins Publish to Bitbucket Plugin < 0.4 - Missing Authorization for Credential ID Enumeration
CVSS 4.3
CVE-2025-64142 MEDIUM
Jenkins Nexus Task Runner Plugin <= 0.9.2 - Missing Authorization for URL Connection
CVSS 4.3
CVE-2025-64139 MEDIUM
Jenkins Start Windocks Containers Plugin < 1.4 - Missing Authorization
CVSS 4.3
CVE-2025-64137 MEDIUM
Jenkins Themis < 1.4.1 - Server-Side Request Forgery via Missing Permission Check
CVSS 4.3
CVE-2025-64132 MEDIUM
Jenkins MCP Server Plugin < 0.84.v50ca_24ef83f2 - Missing Authorization in MCP Tools
CVSS 5.4
CVE-2025-11632 MEDIUM
The Call Now Button - Unauthorized Access
CVSS 4.3
CVE-2025-11587 MEDIUM
The Call Now Button - The #1 Click to Call Button for WordPress <1....
CVSS 4.3
CVE-2025-64285 MEDIUM
Premmerce Wholesale Pricing <1.1.11 - RCE
CVSS 5.4
Details
Vulnerabilities 8,324
Exploit Likelihood High