VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 400 of 464
  • CVE-2025-44001MedAug 11, 2025
    risk 0.26cvss 4.0epss 0.00

    Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Channel Subscriptions details endpoint.

  • CVE-2024-6631MedAug 24, 2024
    risk 0.26cvss 5.0epss 0.00

    The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 3.1.14. This makes it possible for authenticated attackers, with…

  • CVE-2024-5318MedMay 24, 2024
    risk 0.26cvss 4.0epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from 16.11 prior to 16.11.3, and starting from 17.0 prior to 17.0.1. A Guest user can view dependency lists of private projects through job artifacts.

  • CVE-2024-0453MedMay 22, 2024
    risk 0.26cvss 5.0epss 0.00

    The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with…

  • CVE-2024-0452MedMay 22, 2024
    risk 0.26cvss 5.0epss 0.00

    The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with…

  • CVE-2024-0451MedMay 22, 2024
    risk 0.26cvss 5.0epss 0.00

    The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback function in all versions up to, and including, 5.3.4. This makes it possible for authenticated attackers, with subscriber-level…

  • CVE-2023-4630MedSep 11, 2023
    risk 0.26cvss 5.0epss 0.00

    An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 in which any user can read limited information about any project's imports.

  • CVE-2022-39335MedMay 26, 2023
    risk 0.26cvss 5.0epss 0.01

    Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix Federation API allows remote homeservers to request the authorization events in a room. This is necessary so that a homeserver receiving some events can validate that…

  • CVE-2023-29529MedApr 14, 2023
    risk 0.26cvss 5.0epss 0.01

    matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. An attacker present in a room where an MSC3401 group call is taking place can eavesdrop on the video and audio of participants using matrix-js-sdk, without their knowledge. To affected matrix-js-sdk…

  • CVE-2022-36856MedSep 9, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Telecom application prior to SMR Sep-2022 Release 1 allows attacker to start emergency calls via undefined permission.

  • CVE-2021-25519MedDec 8, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without permission.

  • CVE-2026-55483MedAug 19, 2026
    risk 0.25cvss epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission can submit the admin permission while creating a user because store() in app/Http/Controllers/Users/UsersController.php strips superuser permission but does not…

  • CVE-2026-69090MedAug 3, 2026
    risk 0.25cvss 4.9epss 0.00

    Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a role UUID from another organization to…

  • CVE-2026-45330MedJul 31, 2026
    risk 0.25cvss 4.9epss 0.00

    Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin controllers load pending Authorization records by raw identifier without confirming current_organization…

  • CVE-2026-50282MedJul 2, 2026
    risk 0.25cvss epss 0.00

    Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above prior to 4.17.14 contain an authorization issue where a forced folder move can delete a conflicting destination folder without destination delete…

  • CVE-2026-30889MedMar 20, 2026
    risk 0.25cvss 4.9epss 0.00

    Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a moderator could exploit insufficient authorization checks to access metadata of posts they should not have permission to view. Versions 2026.3.0-latest.1, 2026.2.1,…

  • CVE-2026-27150LowFeb 26, 2026
    risk 0.25cvss 3.8epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, missing `validate_before_create` authorization in Data Explorer's `QueryGroupBookmarkable` allows any logged-in user to create bookmarks for query groups they don't have access…

  • CVE-2026-25423LowFeb 19, 2026
    risk 0.25cvss 3.8epss 0.00

    Missing Authorization vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real 3D FlipBook: from n/a through <= 4.19.1.

  • CVE-2025-69015LowDec 30, 2025
    risk 0.25cvss 3.8epss 0.00

    Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crowdsignal Forms: from n/a through <= 1.7.2.

  • CVE-2025-64350LowOct 31, 2025
    risk 0.25cvss 3.8epss 0.00

    Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO: from n/a through <= 1.0.252.1.