VYPR

CWE-266

Incorrect Privilege Assignment

BaseDraft

Description

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

CVEs mapped to this weakness (1,181)

page 2 of 60
  • CVE-2026-73347CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.

  • CVE-2026-66424CriAug 13, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.

  • CVE-2026-66662CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.

  • CVE-2026-65507CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.

  • CVE-2026-54807CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.

  • CVE-2026-49058CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.

  • CVE-2026-27395CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.

  • CVE-2025-69179CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions.

  • CVE-2026-39583CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.

  • CVE-2026-34901CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.

  • CVE-2026-49060CriJun 11, 2026
    risk 0.64cvss 9.8epss 0.02

    Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4.

  • CVE-2025-53209CriJun 2, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0.

  • CVE-2026-48879CriJun 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.

  • CVE-2026-42680CriJun 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 29.0.1.

  • CVE-2026-42758CriMay 27, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through < 4.08.253.

  • CVE-2026-42731CriMay 27, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through <= 5.4.9.

  • CVE-2026-42368CriMay 4, 2026
    risk 0.64cvss 9.9epss 0.01

    A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability.

  • CVE-2026-22337CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Social Login: from n/a before 2.1.4.

  • CVE-2026-33519CriApr 21, 2026
    risk 0.64cvss 9.8epss 0.00

    An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

  • CVE-2026-33518CriApr 21, 2026
    risk 0.64cvss 9.8epss 0.00

    An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.