CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (10,110)
page 496 of 506| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-34050 | Med | 0.00 | 6.5 | 0.00 | Jul 6, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Settings/Updates Livewire component does not check isInstanceAdmin in its mount method, allowing non-admin users to access the Updates settings page… | ||
| CVE-2026-14800 | Med | 0.00 | 4.3 | 0.00 | Jul 6, 2026 | A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. The affected element is an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been made… | ||
| CVE-2026-6509 | Hig | 0.00 | 7.8 | 0.00 | Jul 5, 2026 | Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Privilege Escalation. This issue affects Pardus Update: from <=0.6.3 before 0.6.6. | ||
| CVE-2026-14460 | Hig | 0.00 | 8.8 | 0.00 | Jul 3, 2026 | Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from <= 1.0.4 before 1.0.5. | ||
| CVE-2026-11398 | Med | 0.00 | 5.3 | 0.01 | Jul 3, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This… | ||
| CVE-2026-9230 | Med | 0.00 | 4.3 | 0.00 | Jul 3, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | ||
| CVE-2026-12557 | Med | 0.00 | 5.3 | 0.00 | Jul 3, 2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated… | ||
| CVE-2026-12729 | Med | 0.00 | 4.3 | 0.00 | Jul 3, 2026 | The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.3.0. This is due to a missing capability check on the do_migration() function registered as the… | ||
| CVE-2026-59097 | Med | 0.00 | 5.3 | 0.01 | Jul 2, 2026 | Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by exploiting unprotected POST endpoints on the user-story, task, and issue due-date API viewsets. Attackers can… | ||
| CVE-2026-57760 | Med | 0.00 | 5.3 | 0.00 | Jul 2, 2026 | Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29. | ||
| CVE-2026-57750 | Med | 0.00 | 5.3 | 0.00 | Jul 2, 2026 | Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions. | ||
| CVE-2026-57746 | Hig | 0.00 | 7.1 | 0.00 | Jul 2, 2026 | Subscriber Broken Access Control in Booked <= 3.0.0 versions. | ||
| CVE-2026-57731 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Contributor Broken Access Control in Flatsome <= 3.20.5 versions. | ||
| CVE-2026-57730 | Med | 0.00 | 4.3 | 0.00 | Jul 2, 2026 | Subscriber Broken Access Control in Flatsome <= 3.20.5 versions. | ||
| CVE-2026-57689 | Med | 0.00 | 4.3 | 0.00 | Jul 2, 2026 | Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions. | ||
| CVE-2026-57688 | Hig | 0.00 | 8.2 | 0.00 | Jul 2, 2026 | Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions. | ||
| CVE-2026-57685 | Med | 0.00 | 4.3 | 0.00 | Jul 2, 2026 | Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions. | ||
| CVE-2026-57669 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions. | ||
| CVE-2026-57355 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions. | ||
| CVE-2026-57353 | Med | 0.00 | 6.5 | 0.00 | Jul 2, 2026 | Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions. |
- risk 0.00cvss 6.5epss 0.00
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Settings/Updates Livewire component does not check isInstanceAdmin in its mount method, allowing non-admin users to access the Updates settings page…
- risk 0.00cvss 4.3epss 0.00
A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. The affected element is an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been made…
- risk 0.00cvss 7.8epss 0.00
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Privilege Escalation. This issue affects Pardus Update: from <=0.6.3 before 0.6.6.
- risk 0.00cvss 8.8epss 0.00
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from <= 1.0.4 before 1.0.5.
- risk 0.00cvss 5.3epss 0.01
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…
- risk 0.00cvss 4.3epss 0.00
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
- risk 0.00cvss 5.3epss 0.00
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated…
- risk 0.00cvss 4.3epss 0.00
The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.3.0. This is due to a missing capability check on the do_migration() function registered as the…
- risk 0.00cvss 5.3epss 0.01
Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by exploiting unprotected POST endpoints on the user-story, task, and issue due-date API viewsets. Attackers can…
- risk 0.00cvss 5.3epss 0.00
Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.
- risk 0.00cvss 7.1epss 0.00
Subscriber Broken Access Control in Booked <= 3.0.0 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Broken Access Control in Flatsome <= 3.20.5 versions.
- risk 0.00cvss 4.3epss 0.00
Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.
- risk 0.00cvss 4.3epss 0.00
Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.
- risk 0.00cvss 8.2epss 0.00
Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.
- risk 0.00cvss 4.3epss 0.00
Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
- risk 0.00cvss 6.5epss 0.00
Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.