VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,261)

page 16 of 464
  • CVE-2026-6512CriMay 14, 2026
    risk 0.59cvss 9.1epss 0.00

    The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…

  • CVE-2026-31242CriMay 12, 2026
    risk 0.59cvss 9.1epss 0.00

    The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoint. An unauthenticated attacker can send a DELETE request that triggers a reset operation, leading to the execution of a DROP TABLE…

  • CVE-2026-4119CriApr 22, 2026
    risk 0.59cvss 9.1epss 0.01

    The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin_post action hooks for creating tables (admin_post_add_table) and deleting tables (admin_post_delete_db_table) without…

  • CVE-2026-4365CriApr 14, 2026
    risk 0.59cvss 9.1epss 0.01

    The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` function in all versions up to, and including, 4.3.2.8. The plugin exposes a `wp_rest` nonce in public frontend HTML (`lpData`) to…

  • CVE-2026-34184CriApr 9, 2026
    risk 0.59cvss 9.1epss 0.00

    AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database. This issue was fixed…

  • CVE-2026-27071CriMar 25, 2026
    risk 0.59cvss 9.1epss 0.00

    Missing Authorization vulnerability in Arraytics WPCafe wp-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCafe: from n/a through <= 3.0.7.

  • CVE-2026-4283CriMar 24, 2026
    risk 0.59cvss 9.1epss 0.00

    The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accepting a `process_now` parameter from unauthenticated users, which bypasses the…

  • CVE-2026-30970CriMar 10, 2026
    risk 0.59cvss 9.1epss 0.00

    Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1.1.0, Coral Server allowed the creation of agent sessions through the /api/v1/sessions endpoint without strong authentication.…

  • CVE-2025-11158CriMar 10, 2026
    risk 0.59cvss 9.1epss 0.00

    Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE.

  • CVE-2025-41765CriMar 9, 2026
    risk 0.59cvss 9.1epss 0.00

    Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary data. This includes, but is not limited to, contact images, HTTPS certificates, system backups for restoration, server peer…

  • CVE-2025-41764CriMar 9, 2026
    risk 0.59cvss 9.1epss 0.00

    Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary updates.

  • CVE-2026-3432CriMar 2, 2026
    risk 0.59cvss 9.1epss 0.00

    On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAccountUserId` and `providerId` parameters. An unauthenticated attacker can retrieve OAuth access tokens for any…

  • CVE-2025-70146CriFeb 18, 2026
    risk 0.59cvss 9.1epss 0.00

    Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected…

  • CVE-2026-25876CriFeb 9, 2026
    risk 0.59cvss 9.1epss 0.00

    PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/results.routes.ts verify authentication but fails to enforce object-level authorization (ownership checks). For example, this can be used to return all…

  • CVE-2026-25810CriFeb 9, 2026
    risk 0.59cvss 9.1epss 0.00

    PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/student.submission.routes.ts verify authentication but fails to enforce object-level authorization (ownership checks).

  • CVE-2025-70985CriJan 23, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.

  • CVE-2025-14741CriJan 9, 2026
    risk 0.59cvss 9.1epss 0.00

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a missing capability check on the 'delete_object' function in all versions up to, and including, 3.28.25. This makes it possible for…

  • CVE-2025-13828CriDec 2, 2025
    risk 0.59cvss epss 0.00

    SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain…

  • CVE-2025-65669CriNov 26, 2025
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or authentication checks, bypassing the expected admin-only deletion restriction.

  • CVE-2025-65021CriNov 19, 2025
    risk 0.59cvss 9.1epss 0.00

    Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability exists in the poll finalization feature of the application. Any authenticated user can finalize a poll they do not own by manipulating the…