VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,259)

page 5 of 463
  • CVE-2025-68270CriDec 16, 2025
    risk 0.64cvss 9.9epss 0.00

    The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, CourseLimitedStaffRole users are able to access and edit courses in studio if they are granted the role on an org rather than on a course, and…

  • CVE-2025-12963CriDec 12, 2025
    risk 0.64cvss 9.8epss 0.00

    The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.2.29. This is due to the plugin not properly validating a user's…

  • CVE-2023-53740CriDec 10, 2025
    risk 0.64cvss 9.8epss 0.01

    Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password…

  • CVE-2020-36902CriDec 10, 2025
    risk 0.64cvss 9.8epss 0.01

    UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulating the 'ft[grp]' parameter. Attackers can send a GET request to /html/user with 'ft[grp]' set to integer value '3' to gain super…

  • CVE-2025-12158CriNov 4, 2025
    risk 0.64cvss 9.8epss 0.00

    The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the suc_submit_capabilities() function in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to elevate the role…

  • CVE-2024-13994CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials for other users without proper authorization. This can lead to unauthorized…

  • CVE-2025-59827CriSep 24, 2025
    risk 0.64cvss 9.8epss 0.00

    Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper access control, allowing any authenticated user to assign high-privilege badges (e.g., Staff) to themselves. This could lead to privilege escalation and…

  • CVE-2025-59828CriSep 24, 2025
    risk 0.64cvss 9.8epss 0.00

    Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions 2.0+, Yarn plugins are auto-executed when running yarn --version. This could lead to a bypass of the directory trust dialog in Claude Code, as plugins would be…

  • CVE-2025-9054CriSep 24, 2025
    risk 0.64cvss 9.8epss 0.00

    The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'wcmlim_settings_ajax_handler' function in all versions up to,…

  • CVE-2025-10690CriSep 19, 2025
    risk 0.64cvss 9.8epss 0.01

    The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads due to a missing capability check on the 'beplus_import_pack_install_plugin' function in all versions up to, and including, 3.2.2. This makes it possible for…

  • CVE-2024-32832CriAug 31, 2025
    risk 0.64cvss 9.8epss 0.00

    Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.6.93.

  • CVE-2025-54943CriAug 30, 2025
    risk 0.64cvss 9.8epss 0.01

    A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized application deployment due to the absence of proper access control checks.

  • CVE-2025-52352CriAug 21, 2025
    risk 0.64cvss 9.8epss 0.01

    Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed deployments by hiding the sign-up option on the login page UI. However, the sign-up API endpoint remains publicly accessible and functional, allowing…

  • CVE-2025-6380CriJul 24, 2025
    risk 0.64cvss 9.8epss 0.01

    The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its oo.callback REST endpoint in versions 1.1.0 to 2.2.0. The plugin’s permission callback only verifies that the supplied, encrypted attachment ID maps to an…

  • CVE-2025-6187CriJul 22, 2025
    risk 0.64cvss 9.8epss 0.01

    The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_info REST endpoint in versions 1.3.7 through 1.7.9. The plugin registers the /webhook/v2/order_info/ route with a permission_callback that always returns true,…

  • CVE-2025-49747CriJul 18, 2025
    risk 0.64cvss 9.9epss 0.01

    Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-5304CriJun 28, 2025
    risk 0.64cvss 9.8epss 0.01

    The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() function in versions 1.0.0 through 1.1.3. This makes it possible for unauthenticated attackers to elevate their privileges to that of…

  • CVE-2024-53298CriJun 20, 2025
    risk 0.64cvss 9.8epss 0.00

    Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS export. An unauthenticated attacker with remote access could potentially exploit this vulnerability leading to unauthorized filesystem access. The attacker may be…

  • CVE-2025-5288CriJun 13, 2025
    risk 0.64cvss 9.8epss 0.01

    The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the process_handler() function in versions 1.0.0 to 2.0.3. This makes it possible for unauthenticated…

  • CVE-2025-5486CriJun 6, 2025
    risk 0.64cvss 9.8epss 0.00

    The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the WPMDBUG_handle_settings() function in versions 1.0 to 1.1.0. This makes it possible for unauthenticated attackers to enable debugging and send all emails to an…