VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,267)

page 429 of 464
  • CVE-2026-26979LowFeb 26, 2026
    risk 0.18cvss 2.7epss 0.00

    Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users are able to close, archive and pin topics in private categories they don't have access to. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patch the issue. No known…

  • CVE-2025-14270LowFeb 19, 2026
    risk 0.18cvss 2.7epss 0.00

    The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action in the wa_order_number_save_number_field function. This…

  • CVE-2026-1831LowFeb 18, 2026
    risk 0.18cvss 2.7epss 0.00

    The YayMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized plugin installation and activation due to missing capability checks on the 'yaymail_install_yaysmtp' AJAX action and `/yaymail/v1/addons/activate` REST endpoint in all versions up to,…

  • CVE-2025-14573LowFeb 16, 2026
    risk 0.18cvss 3.8epss 0.00

    Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users to their team via API requests. Mattermost Advisory ID: MMSA-2025-00561

  • CVE-2025-68585LowDec 24, 2025
    risk 0.18cvss 2.7epss 0.00

    Missing Authorization vulnerability in Ben Balter WP Document Revisions wp-document-revisions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Document Revisions: from n/a through <= 3.7.2.

  • CVE-2025-54004LowDec 16, 2025
    risk 0.18cvss 2.7epss 0.00

    Missing Authorization vulnerability in WC Lovers WCFM – Frontend Manager for WooCommerce wc-frontend-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM – Frontend Manager for WooCommerce: from n/a through <= 6.7.24.

  • CVE-2025-64255LowDec 9, 2025
    risk 0.18cvss 2.7epss 0.00

    Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin and Site Enhancements (ASE): from n/a through <= 8.0.8.

  • CVE-2025-64254LowDec 9, 2025
    risk 0.18cvss 2.7epss 0.00

    Missing Authorization vulnerability in Ronald Huereca Photo Block photo-block allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Block: from n/a through <= 1.5.1.

  • CVE-2025-64681LowNov 10, 2025
    risk 0.18cvss 2.7epss 0.00

    In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations

  • CVE-2025-64352LowOct 31, 2025
    risk 0.18cvss 2.7epss 0.00

    Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n/a through <= 6.2.4.

  • CVE-2025-10173LowSep 26, 2025
    risk 0.18cvss 2.7epss 0.00

    The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized access due to an incorrect capability check on the post_save() function in all versions up to, and including, 4.8.3. This makes it possible…

  • CVE-2025-53113LowJul 30, 2025
    risk 0.18cvss 2.7epss 0.00

    GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 0.65 through 10.0.18, a technician can use the external links…

  • CVE-2025-5846LowJun 26, 2025
    risk 0.18cvss 2.7epss 0.00

    An issue has been discovered in GitLab EE affecting all versions from 16.10 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to assign unrelated compliance frameworks to projects by sending crafted GraphQL mutations that…

  • CVE-2025-30877LowMar 27, 2025
    risk 0.18cvss 2.7epss 0.00

    Missing Authorization vulnerability in fatcatapps Quiz Cat quiz-cat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz Cat: from n/a through <= 3.0.8.

  • CVE-2024-51671LowNov 19, 2024
    risk 0.18cvss 2.7epss 0.00

    Missing Authorization vulnerability in Themeisle Otter - Gutenberg Block otter-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Otter - Gutenberg Block: from n/a through <= 3.0.3.

  • CVE-2024-8350LowSep 25, 2024
    risk 0.18cvss 2.7epss 0.00

    The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint in all versions up to, and including, 6.1.0.1. This makes it possible for authenticated…

  • CVE-2024-41728LowSep 10, 2024
    risk 0.18cvss 2.7epss 0.00

    Due to missing authorization check, SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker logged in as a developer to read objects contained in a package. This causes an impact on confidentiality, as this attacker would otherwise not have access to view…

  • CVE-2023-49652LowNov 29, 2023
    risk 0.18cvss 2.7epss 0.01

    Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate system-scoped credentials IDs of credentials…

  • CVE-2023-4304LowAug 11, 2023
    risk 0.18cvss 3.8epss 0.01

    Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.

  • CVE-2023-3587LowJul 17, 2023
    risk 0.18cvss 2.7epss 0.00

    Mattermost fails to properly show information in the UI, allowing a system admin to modify a board state allowing any user with a valid sharing link to join the board with editor access, without the UI showing the updated permissions.