VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,117)

page 494 of 506
  • CVE-2026-47422MedJul 10, 2026
    risk 0.00cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This vulnerability is fixed in 15.107.5 and 16.18.2.

  • CVE-2026-13039MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.00

    The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This is due to the plugin not properly verifying that a user is…

  • CVE-2026-1667HigJul 10, 2026
    risk 0.00cvss 7.2epss 0.00

    The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting in all versions up to, and including, 14.0.0 due to a leak of an API token and insufficient input sanitization and output escaping. This makes it possible…

  • CVE-2026-61441MedJul 10, 2026
    risk 0.00cvss 6.5epss 0.00

    PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either endpoint of a dependency edge and checks delete permission only against the caller-selected URL issue. A workspace member who…

  • CVE-2026-59796HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.00

    In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks

  • CVE-2026-9857MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…

  • CVE-2026-11990MedJul 10, 2026
    risk 0.00cvss 5.3epss 0.01

    The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-1946MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gwaiwebu_gravitywrite_disconnect_handler() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated…

  • CVE-2026-15026MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and above,…

  • CVE-2026-11992MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…

  • CVE-2026-15293HigJul 10, 2026
    risk 0.00cvss 8.0epss 0.01

    The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated…

  • CVE-2026-15291HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.01

    The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the REST API endpoints /wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id}. This is due to the plugin…

  • CVE-2026-11818MedJul 10, 2026
    risk 0.00cvss 5.4epss 0.00

    The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.14. This is due to the plugin not properly verifying that a user is authorized to perform an action.…

  • CVE-2026-15320MedJul 10, 2026
    risk 0.00cvss 5.4epss 0.00

    A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function rt.ReloadConfig of the file pkg/channels/pico/pico.go. Performing a manipulation of the argument message.send results in missing authorization. It is possible to initiate the…

  • CVE-2026-59853MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint returns saved search criteria from data/storage/criteria.json without the publish-access filtering used by sibling storage endpoints, allowing a publish-mode…

  • CVE-2026-33802MedJul 9, 2026
    risk 0.00cvss 5.5epss 0.00

    A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS). On EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400 switches, an authenticated, local attacker with…

  • CVE-2026-12593HigJul 9, 2026
    risk 0.00cvss —epss 0.00

    The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for creating an API Token for another user had sufficient permission to do so. Precondition for successful exploitation…

  • CVE-2026-9240MedJul 9, 2026
    risk 0.00cvss 4.3epss 0.00

    The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the updateShippingMethod() function (registered to the wp_ajax_lpc_order_affect AJAX action) in versions…

  • CVE-2026-9237MedJul 9, 2026
    risk 0.00cvss 4.3epss 0.00

    The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…

  • CVE-2026-9235MedJul 9, 2026
    risk 0.00cvss 4.3epss 0.00

    The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and missing nonce verification on the create_label() and delete_label() functions in versions up to, and including,…