VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,489)

page 179 of 475
  • CVE-2026-40185HigApr 10, 2026
    risk 0.39cvss 7.1epss 0.00

    TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authorization checks on the Immich trip photo management routes. This vulnerability is fixed in 2.7.2.

  • CVE-2026-34053HigMar 26, 2026
    risk 0.39cvss 7.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorization in the AJAX deletion endpoint `interface/forms/procedure_order/handle_deletions.php` allows any authenticated user, regardless…

  • CVE-2026-30926HigMar 10, 2026
    risk 0.39cvss 7.1epss 0.00

    SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the publish service of SiYuan Note that allows low-privilege publish accounts (RoleReader) to modify notebook content via the /api/block/appendHeadingChildren API…

  • CVE-2026-27638HigFeb 26, 2026
    risk 0.39cvss 7.1epss 0.00

    Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify that the authenticated user owns or has access to the file being operated on. Any authenticated user can read, modify, and…

  • CVE-2025-13772HigJan 9, 2026
    risk 0.39cvss 7.1epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorized namespaces by manipulating namespace…

  • CVE-2025-5018HigJun 6, 2025
    risk 0.39cvss 7.1epss 0.00

    The Hive Support plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the hs_update_ai_chat_settings() and hive_lite_support_get_all_binbox() functions in all versions up to, and including, 1.2.5. This makes it…

  • CVE-2024-11840HigDec 11, 2024
    risk 0.39cvss 7.1epss 0.00

    The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the uucss_data, update_rapidload_settings, wp_ajax_update_htaccess_file, uucss_update_rule,…

  • CVE-2024-43235HigNov 1, 2024
    risk 0.39cvss 7.1epss 0.00

    Missing Authorization vulnerability in MetaBox.Io Meta Box – WordPress Custom Fields Framework allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Meta Box – WordPress Custom Fields Framework: from n/a through 5.9.10.

  • CVE-2022-25768HigSep 18, 2024
    risk 0.39cvss 7.0epss 0.00

    The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker to access the Mautic version number or to execute parts of…

  • CVE-2024-45050HigSep 4, 2024
    risk 0.39cvss 7.1epss 0.00

    Ringer server is the server code for the Ringer messaging app. Prior to version 1.3.1, there is an issue with the messages loading route where Ringer Server does not check to ensure that the user loading the conversation is actually a member of that conversation. This allows any…

  • CVE-2024-1937HigJul 16, 2024
    risk 0.39cvss 7.1epss 0.00

    The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_item' function in all versions up to, and including, 2.4.44. This makes it possible for authenticated attackers, with contributor…

  • CVE-2024-4958HigJun 1, 2024
    risk 0.39cvss 7.1epss 0.00

    The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_form_action' function in versions up to, and including,…

  • CVE-2024-4566HigMay 21, 2024
    risk 0.39cvss 7.1epss 0.00

    The ShopLentor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_dismiss function in all versions up to, and including, 2.8.8. This makes it possible for authenticated attackers, with contributor-level access…

  • CVE-2023-35937MedJul 6, 2023
    risk 0.39cvss 6.0epss 0.01

    Metersphere is an open source continuous testing platform. In versions prior to 2.10.2 LTS, some key APIs in Metersphere lack permission checks. This allows ordinary users to execute APIs that can only be executed by space administrators or project administrators. For example,…

  • CVE-2022-0905HigMar 10, 2022
    risk 0.39cvss 7.1epss 0.01

    Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.

  • CVE-2022-0588HigFeb 15, 2022
    risk 0.39cvss 7.1epss 0.01

    Missing Authorization in Packagist librenms/librenms prior to 22.2.0.

  • CVE-2021-25095HigFeb 7, 2022
    risk 0.39cvss 7.1epss 0.01

    The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber to call it and block arbitrary country, or block all of them…

  • CVE-2021-32015MedJun 8, 2021
    risk 0.39cvss 6.0epss 0.00

    In Nuvoton NPCT75x TPM 1.2 firmware 7.4.0.0, a local authenticated malicious user with high privileges could potentially gain unauthorized access to TPM non-volatile memory. NOTE: Upgrading to firmware version 7.4.0.1 will mitigate against the vulnerability, but version 7.4.0.1…

  • CVE-2019-20676MedApr 15, 2020
    risk 0.39cvss 6.0epss 0.00

    Certain NETGEAR devices are affected by lack of access control at the function level. This affects FS728TLP before 1.0.1.26, GS105Ev2 before 1.6.0.4, GS105PE before 1.6.0.4, GS108Ev3 before 2.06.08, GS108PEv3 before 2.06.08, GS110EMX before 1.0.1.4, GS116Ev2 before 2.6.0.35,…

  • CVE-2019-0201MedMay 23, 2019
    risk 0.39cvss 5.9epss 0.10

    An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string.…