VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,043)

page 492 of 503
  • CVE-2026-13537MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack may be launched remotely. The exploit has been made public and could be used.

  • CVE-2026-9233MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-3462MedJun 27, 2026
    risk 0.00cvss 6.5epss 0.00

    The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'upload_csv' and 'process_batch' functions in all versions up to, and including, 1.8.9. This makes it possible for authenticated attackers, with…

  • CVE-2026-12471MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plugin function in all versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

  • CVE-2026-12432MedJun 27, 2026
    risk 0.00cvss 5.3epss 0.01

    The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying…

  • CVE-2026-11773MedJun 27, 2026
    risk 0.00cvss 4.3epss 0.00

    The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-12404MedJun 27, 2026
    risk 0.00cvss 5.3epss 0.00

    The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible…

  • CVE-2026-55838MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.7 and earlier, the real-time metrics endpoint at /rustfs/admin/v3/metrics is accessible to any valid IAM user regardless of their assigned policy. Every other admin handler in the codebase calls…

  • CVE-2026-55189HigJun 26, 2026
    risk 0.00cvss 7.7epss 0.00

    RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read and probe handlers dispatch directly to the storage backend without ever calling the IAM authorization function that the FTP…

  • CVE-2026-55188HigJun 26, 2026
    risk 0.00cvss 8.2epss 0.00

    RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication admin API. The ListRemoteTargetHandler handler for listing remote replication targets only checks whether request…

  • CVE-2026-49991HigJun 26, 2026
    risk 0.00cvss 8.6epss 0.00

    RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the Snowball auto-extract feature to write arbitrary objects into other users'…

  • CVE-2026-47193HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing object and field visibility. This vulnerability is fixed in 17.3.3 and 17.4.1.

  • CVE-2026-44734MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenProject's CostReportsController. The rename and update actions allow any authenticated user to modify the name, filters, and…

  • CVE-2026-57518HigJun 26, 2026
    risk 0.00cvss 8.8epss 0.01

    Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitrary custom roles to themselves due to missing authorization checks in…

  • CVE-2026-57661MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.

  • CVE-2026-57660MedJun 26, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.

  • CVE-2026-57654MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.

  • CVE-2026-57649MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.

  • CVE-2026-57648MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.

  • CVE-2026-57645HigJun 26, 2026
    risk 0.00cvss 8.1epss 0.00

    newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.