VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,489)

page 174 of 475
  • CVE-2022-36352MedJan 8, 2024
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a through 5.0.3.

  • CVE-2023-46212MedDec 19, 2023
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra allows Accessing Functionality Not Properly Constrained by ACLs, Cross Site Request Forgery.This issue affects WP EXtra: from n/a through 6.2.

  • CVE-2023-6394HigDec 9, 2023
    risk 0.41cvss 7.4epss 0.01

    A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access…

  • CVE-2023-3999MedAug 31, 2023
    risk 0.41cvss 6.3epss 0.00

    The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on its AJAX calls in versions up to, and including, 0.6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and…

  • CVE-2023-4106MedAug 11, 2023
    risk 0.41cvss 6.3epss 0.00

    Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks.

  • CVE-2023-35164MedJun 26, 2023
    risk 0.41cvss 6.3epss 0.00

    DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions a missing authorization check allows unauthorized users to manipulate a dashboard created by the administrator. This vulnerability has been…

  • CVE-2021-4366MedJun 7, 2023
    risk 0.41cvss 6.3epss 0.01

    The PWA for WP & AMP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the pwaforwp_update_features_options function in versions up to, and including, 1.7.32. This makes it possible for authenticated attackers to change the…

  • CVE-2020-36715HigJun 7, 2023
    risk 0.41cvss 7.4epss 0.01

    The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions up to, and including, 1.4. This makes it possible for authenticated attackers to inject arbitrary web scripts into the plugin…

  • CVE-2022-4937MedApr 5, 2023
    risk 0.41cvss 6.3epss 0.01

    The WCFM Frontend Manager plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 6.6.0 due to missing capability checks on various AJAX actions. This makes it possible for authenticated attackers, with minimal…

  • CVE-2020-36670MedMar 7, 2023
    risk 0.41cvss 6.3epss 0.01

    The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to, and including 7.7.1 due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber level…

  • CVE-2023-22478HigJan 14, 2023
    risk 0.41cvss 7.3epss 0.04

    KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. This issue has been patched in version 1.6.4. There are currently no known workarounds.

  • CVE-2022-2696MedNov 3, 2022
    risk 0.41cvss 6.3epss 0.01

    The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation. This makes it possible for…

  • CVE-2021-42851MedMay 18, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account.

  • CVE-2021-21473MedJun 9, 2021
    risk 0.41cvss 6.3epss 0.01

    SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute…

  • CVE-2020-7692HigJul 9, 2020
    risk 0.41cvss 7.4epss 0.02

    PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that…

  • CVE-2018-20501MedDec 30, 2019
    risk 0.41cvss 6.3epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

  • CVE-2019-0386MedNov 13, 2019
    risk 0.41cvss 6.3epss 0.01

    Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA Sales (corrected in S4CORE 1.0, 1.01, 1.02, 1.03, 1.04) does not execute the required authorization checks for an authenticated user, which can result in an…

  • CVE-2026-6471HigAug 13, 2026
    risk 0.40cvss 7.2epss 0.00

    Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. …

  • CVE-2026-69252HigAug 4, 2026
    risk 0.40cvss epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only by the feat:files feature gate and did not enforce checkPermission on GET or DELETE. A low-privileged authenticated API key with…

  • CVE-2026-66311MedAug 4, 2026
    risk 0.40cvss 6.2epss 0.00

    Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.