VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,262)

page 45 of 464
  • CVE-2025-42953HigJul 8, 2025
    risk 0.53cvss 8.1epss 0.00

    SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This could completely compromise the integrity and availability with no impact on confidentiality of the system.

  • CVE-2025-52813HigJul 4, 2025
    risk 0.53cvss 8.1epss 0.00

    Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MobiLoud: from n/a through 4.6.5.

  • CVE-2025-52818HigJun 27, 2025
    risk 0.53cvss 8.2epss 0.00

    Missing Authorization vulnerability in Dejan Jasnic Trusty Whistleblowing trusty-whistleblowing-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trusty Whistleblowing: from n/a through <= 2.0.1.

  • CVE-2025-52817HigJun 27, 2025
    risk 0.53cvss 8.2epss 0.00

    Missing Authorization vulnerability in ZealousWeb Abandoned Contact Form 7 abandoned-contact-form-7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Abandoned Contact Form 7: from n/a through <= 2.2.

  • CVE-2025-39536HigMay 23, 2025
    risk 0.53cvss 8.2epss 0.00

    Missing Authorization vulnerability in Chimpstudio JobHunt Job Alerts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobHunt Job Alerts: from n/a through 3.6.

  • CVE-2025-39352HigMay 19, 2025
    risk 0.53cvss 8.2epss 0.00

    Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant: from n/a through <= 7.0.

  • CVE-2025-39350HigMay 19, 2025
    risk 0.53cvss 8.2epss 0.00

    Missing Authorization vulnerability in Rocket Apps wProject.This issue affects wProject: from n/a before 5.8.0.

  • CVE-2024-58101HigMay 14, 2025
    risk 0.53cvss 8.1epss 0.00

    Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to stop this mode. As a consequence, audio playback takeover or even microphone recording without user consent or notification is achieved. Note: This is considered…

  • CVE-2025-2816HigMay 1, 2025
    risk 0.53cvss 8.1epss 0.00

    The Page View Count plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the yellow_message_dontshow() function in versions 2.8.0 to 2.8.4. This makes it possible for authenticated…

  • CVE-2025-32593HigApr 17, 2025
    risk 0.53cvss 8.2epss 0.00

    Missing Authorization vulnerability in Bytes Technolab Add Product Frontend for WooCommerce add-product-frontend-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Add Product Frontend for WooCommerce: from n/a through <=…

  • CVE-2024-13776HigApr 5, 2025
    risk 0.53cvss 8.1epss 0.00

    The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'dzsap_delete_notice' AJAX action in all versions up to, and…

  • CVE-2025-31678HigMar 31, 2025
    risk 0.53cvss 8.2epss 0.00

    Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.0.3.

  • CVE-2025-26733HigMar 27, 2025
    risk 0.53cvss 8.2epss 0.00

    Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1.

  • CVE-2024-13801HigMar 26, 2025
    risk 0.53cvss 8.1epss 0.00

    The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'baf_set_notice_status' AJAX action in all versions up to, and including, 2.1.4. This makes it…

  • CVE-2024-7767HigMar 20, 2025
    risk 0.53cvss 8.1epss 0.01

    An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system to view, modify, and delete chats created by an Admin. This can lead to unauthorized access to sensitive information, loss of…

  • CVE-2024-10762HigMar 20, 2025
    risk 0.53cvss 8.1epss 0.01

    In lunary-ai/lunary before version 1.5.9, the /v1/evaluators/ endpoint allows users to delete evaluators of a project by sending a DELETE request. However, the route lacks proper access control, such as middleware to ensure that only users with appropriate roles can delete…

  • CVE-2025-0952HigMar 14, 2025
    risk 0.53cvss 8.1epss 0.00

    The Eco Nature - Environment & Ecology WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cmsmasters_hide_admin_notice' AJAX action in all versions up to, and…

  • CVE-2024-13655HigMar 7, 2025
    risk 0.53cvss 8.1epss 0.00

    The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the propanel_of_ajax_callback() function in all versions up to, and including, 3.5.2.…

  • CVE-2024-13556HigFeb 18, 2025
    risk 0.53cvss 8.1epss 0.01

    The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.1 via deserialization of untrusted input from an file export. This makes it possible for…

  • CVE-2025-26377HigFeb 12, 2025
    risk 0.53cvss 8.1epss 0.01

    A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove users via crafted HTTP requests.