VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,262)

page 37 of 464
  • CVE-2026-73608HigAug 13, 2026
    risk 0.56cvss 8.6epss 0.00

    SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4) contains a missing-authorization vulnerability in the /api/av/getAttributeViewSearchTarget endpoint. The route is registered with CheckAuth only and performs…

  • CVE-2026-72798HigAug 12, 2026
    risk 0.56cvss 8.6epss 0.00

    SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to…

  • CVE-2026-72795HigAug 12, 2026
    risk 0.56cvss 8.6epss 0.00

    SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request published blocks containing embed queries to read content from password-protected, hidden, or forbidden…

  • CVE-2026-72789HigAug 12, 2026
    risk 0.56cvss 8.6epss 0.00

    SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API…

  • CVE-2026-22343HigJun 17, 2026
    risk 0.56cvss 8.6epss 0.00

    Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions.

  • CVE-2026-34024HigJun 15, 2026
    risk 0.56cvss epss 0.00

    The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple web application endpoints. An authenticated attacker with minimal privileges can access endpoints that are not visible in the frontend but remain directly…

  • CVE-2026-8077HigMay 8, 2026
    risk 0.56cvss epss 0.00

    Lack of proper authorization implementation in the CashDro 3 web administration panel, version 24.01.00.26. The backend lacks authorization controls, leaving security entirely to the frontend. By modifying the binary string in the ‘Permissions’ field of the JSON response, an…

  • CVE-2026-30920HigMar 10, 2026
    risk 0.56cvss 8.6epss 0.00

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: true without validating that the caller is…

  • CVE-2025-69063HigFeb 20, 2026
    risk 0.56cvss 8.6epss 0.00

    Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects New User Approve: from n/a through <= 3.2.0.

  • CVE-2025-12061HigNov 26, 2025
    risk 0.56cvss 8.6epss 0.00

    The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, allowing unauthenticated users to import and execute arbitrary SQL statements

  • CVE-2025-12384HigNov 5, 2025
    risk 0.56cvss 8.6epss 0.00

    The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized access/modification/loss of data in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to…

  • CVE-2025-49916HigOct 22, 2025
    risk 0.56cvss 8.6epss 0.00

    Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MultiVendorX: from n/a through <= 4.2.23.

  • CVE-2025-59968HigOct 9, 2025
    risk 0.56cvss 8.6epss 0.00

    A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated network-based attacker to read or modify metadata via the web interface.  Tampering with this metadata can result in managed SRX Series devices permitting…

  • CVE-2025-28965HigJul 16, 2025
    risk 0.56cvss 8.6epss 0.00

    Missing Authorization vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects URL Shortener: from n/a through <= 3.0.7.

  • CVE-2025-5121HigJun 20, 2025
    risk 0.56cvss 8.5epss 0.10

    An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.

  • CVE-2025-49181HigJun 12, 2025
    risk 0.56cvss 8.6epss 0.00

    Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTTP POST requests to modify the log files’ root path as well as the TCP ports the service is running on, leading to a…

  • CVE-2025-4430HigMay 14, 2025
    risk 0.56cvss epss 0.00

    Unauthorized access to "/api/Token/gettoken" endpoint in EZD RP allows file manipulation.This issue affects EZD RP in versions before 20.19 (published on 22nd August 2024).

  • CVE-2025-26961HigMar 15, 2025
    risk 0.56cvss 8.6epss 0.00

    Missing Authorization vulnerability in FRESHFACE Fresh Framework fresh-framework allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Fresh Framework: from n/a through <= 1.70.0.

  • CVE-2024-12542HigJan 9, 2025
    risk 0.56cvss 8.6epss 0.01

    The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 0.1.2. This makes it possible for unauthenticated attackers to read configuration settings…

  • CVE-2024-12535HigJan 7, 2025
    risk 0.56cvss 8.6epss 0.01

    The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to read configuration…