VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (5,492)

page 159 of 275
  • CVE-2025-64630MedDec 16, 2025
    risk 0.32cvss 4.9epss 0.00

    Missing Authorization vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business Directory: from n/a through <= 6.4.19.

  • CVE-2025-64251MedDec 16, 2025
    risk 0.32cvss 4.9epss 0.00

    Missing Authorization vulnerability in azzaroco Ultimate Learning Pro indeed-learning-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Learning Pro: from n/a through <= 3.9.3.

  • CVE-2025-60106MedSep 26, 2025
    risk 0.32cvss 4.9epss 0.00

    Missing Authorization vulnerability in Roxnor EmailKit emailkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EmailKit: from n/a through <= 1.6.0.

  • CVE-2025-42949MedAug 12, 2025
    risk 0.32cvss 4.9epss 0.00

    Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging the SQL Console. This could enable an attacker to access and read the contents of database…

  • CVE-2025-42961MedJul 8, 2025
    risk 0.32cvss 4.9epss 0.00

    Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privileges could exploit the insufficient validation of user permissions to access sensitive database tables. By leveraging overly permissive access configurations,…

  • CVE-2025-47465MedMay 7, 2025
    risk 0.32cvss 4.9epss 0.00

    Missing Authorization vulnerability in creativethemeshq Blocksy blocksy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Blocksy: from n/a through <= 2.0.97.

  • CVE-2025-30861MedMar 27, 2025
    risk 0.32cvss 4.9epss 0.01

    Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.6.29.

  • CVE-2024-22272MedJun 27, 2024
    risk 0.32cvss 4.9epss 0.00

    VMware Cloud Director contains an Improper Privilege Management vulnerability. An authenticated tenant administrator for a given organization within VMware Cloud Director may be able to accidentally disable their organization leading to a Denial of Service for active…

  • CVE-2026-42320MedJun 3, 2026
    risk 0.31cvss epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read arbitrary files inside the GLPI_DOC_DIR. Upgrade to 10.0.25 or 11.0.7 to receive a patch.

  • CVE-2026-44448MedMay 13, 2026
    risk 0.31cvss 5.9epss 0.00

    ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permitted role. This vulnerability is fixed in 15.102.0 and 16.11.0.

  • CVE-2026-6663MedMay 12, 2026
    risk 0.31cvss 4.8epss 0.00

    The GWD Connect plugin for WordPress is vulnerable to missing authorization to limited code execution in all versions up to, and including, 2.9. This is due to the plugin's standalone agent endpoints (gwd-backup.php and gwd-logs.php) not verifying authentication when the API key…

  • CVE-2026-40592MedApr 21, 2026
    risk 0.31cvss 5.9epss 0.00

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conversation/undo-reply/{thread_id}` checks only whether the current user can view the parent conversation. It does not verify that the current user created the…

  • CVE-2026-40265MedApr 17, 2026
    risk 0.31cvss 5.9epss 0.00

    Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset download endpoint at /api/notes/{noteID}/assets/{assetID} is registered without authentication middleware, and the backend query does not verify ownership or book visibility. An…

  • CVE-2025-68947MedJan 13, 2026
    risk 0.31cvss 4.7epss 0.00

    NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes by issuing crafted IOCTL requests to the driver.

  • CVE-2025-31606MedMar 31, 2025
    risk 0.31cvss 4.8epss 0.00

    Missing Authorization vulnerability in softpulseinfotech SP Blog Designer sp-blog-designer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SP Blog Designer: from n/a through <= 1.0.0.

  • CVE-2025-27294MedFeb 24, 2025
    risk 0.31cvss 4.8epss 0.00

    Missing Authorization vulnerability in platcom WP-Asambleas wp-asambleas allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-Asambleas: from n/a through <= 2.85.0.

  • CVE-2025-22677MedFeb 3, 2025
    risk 0.31cvss 4.8epss 0.00

    Missing Authorization vulnerability in UIUX Lab Uix Shortcodes uix-shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uix Shortcodes: from n/a through <= 2.0.3.

  • CVE-2023-23895MedDec 9, 2024
    risk 0.31cvss 4.7epss 0.01

    Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through 1.1.82.

  • CVE-2024-53825MedDec 6, 2024
    risk 0.31cvss 4.7epss 0.00

    Missing Authorization vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filebird: from n/a through <= 6.3.2.

  • CVE-2024-6591MedJul 27, 2024
    risk 0.31cvss 5.8epss 0.00

    The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due to a missing capability check on the 'send_auction_email_callback' and 'resend_auction_email_callback' functions in all versions up to, and including, 4.2.7.…