VYPR

CWE-285

Improper Authorization

ClassDraftLikelihood: High

Description

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-104 · CAPEC-127 · CAPEC-13 · CAPEC-17 · CAPEC-39 · CAPEC-402 · CAPEC-45 · CAPEC-5 · CAPEC-51 · CAPEC-59 · CAPEC-60 · CAPEC-647 · CAPEC-668 · CAPEC-76 · CAPEC-77 · CAPEC-87

CVEs mapped to this weakness (1,626)

page 12 of 82
  • CVE-2025-65033HigNov 19, 2025
    risk 0.53cvss 8.1epss 0.00

    Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll management feature allows any authenticated user to pause or resume any poll, regardless of ownership. The system only uses the public pollId to identify polls,…

  • CVE-2025-65029HigNov 19, 2025
    risk 0.53cvss 8.1epss 0.00

    Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows any authenticated user to delete arbitrary participants from polls without ownership verification. The endpoint relies solely on a…

  • CVE-2025-11521HigNov 11, 2025
    risk 0.53cvss 8.1epss 0.00

    The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient validation of remote URLs for zip downloads and an easily guessable key in all versions up to, and including, 0.2. This makes it possible for…

  • CVE-2025-49594CriOct 6, 2025
    risk 0.53cvss epss 0.01

    XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Starting in version 2.17.1 and prior to version 2.18.2, anyone with VIEW access to a user profile can create a token for that user. If that XWiki instance is configured to allow token authentication, it…

  • CVE-2025-43585HigJun 10, 2025
    risk 0.53cvss 8.2epss 0.00

    Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain…

  • CVE-2025-3921HigMay 7, 2025
    risk 0.53cvss 8.2epss 0.00

    The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handel_ajax_req() function in versions 1.9.1 to 7.5.2. This makes it possible for unauthenticated attackers to update…

  • CVE-2025-26683HigMar 31, 2025
    risk 0.53cvss 8.1epss 0.01

    Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-24418HigFeb 11, 2025
    risk 0.53cvss 8.1epss 0.01

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures…

  • CVE-2025-24409HigFeb 11, 2025
    risk 0.53cvss 8.2epss 0.01

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain…

  • CVE-2024-13646HigJan 30, 2025
    risk 0.53cvss 8.1epss 0.00

    The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on the 'single_user_chat_update_login' function in all versions up to, and including, 0.5. This makes it possible for…

  • CVE-2024-52528CriNov 15, 2024
    risk 0.53cvss epss 0.01

    Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for Budget Control. Budget Control Gateway does not properly validate auth tokens, which allows attackers to bypass intended restrictions. This vulnerability is…

  • CVE-2024-43460HigSep 17, 2024
    risk 0.53cvss 8.1epss 0.01

    Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.

  • CVE-2024-7624HigAug 15, 2024
    risk 0.53cvss 8.1epss 0.00

    The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable access to the plugin's settings…

  • CVE-2024-37282HigJun 28, 2024
    risk 0.53cvss 8.1epss 0.01

    It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create new API keys that have elevated privileges.

  • CVE-2024-2441HigMay 14, 2024
    risk 0.53cvss 8.1epss 0.01

    The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin…

  • CVE-2023-6538HigDec 11, 2023
    risk 0.53cvss 7.6epss 0.02

    SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to…

  • CVE-2023-41841HigOct 10, 2023
    risk 0.53cvss 8.1epss 0.01

    An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belonging to the prof-admin profile to perform elevated actions.

  • CVE-2023-28385HigAug 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Improper authorization in the Intel(R) NUC Pro Software Suite for Windows before version 2.0.0.9 may allow a privileged user to potentially enable escalation of privilage via local access.

  • CVE-2022-0993HigApr 19, 2022
    risk 0.53cvss 8.1epss 0.07

    The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on the 2FA back-up code implementation that logs users in upon success. This affects…

  • CVE-2021-27663HigAug 30, 2021
    risk 0.53cvss 8.2epss 0.02

    A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequate authorization. This issue affects: Johnson Controls CEM Systems AC2000 10.1; 10.2; 10.3; 10.4; 10.5.