CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (10,117)
page 500 of 506| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-57430 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions. | ||
| CVE-2026-57324 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions. | ||
| CVE-2026-57323 | Med | 0.00 | 5.8 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions. | ||
| CVE-2026-56063 | Hig | 0.00 | 8.3 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions. | ||
| CVE-2026-56061 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions. | ||
| CVE-2026-56038 | Hig | 0.00 | 8.8 | 0.00 | Jun 26, 2026 | Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions. | ||
| CVE-2026-56025 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions. | ||
| CVE-2026-54847 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions. | ||
| CVE-2026-54846 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Syncee Premium Dropshipping & Wholesale <= 1.0.27 versions. | ||
| CVE-2026-54840 | Hig | 0.00 | 7.3 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Newsletters <= 4.13 versions. | ||
| CVE-2026-54837 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Intranet & Private Site – All-In-One Intranet <= 1.8.1 versions. | ||
| CVE-2026-54835 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions. | ||
| CVE-2026-54832 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions. | ||
| CVE-2026-52701 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions. | ||
| CVE-2026-24547 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions. | ||
| CVE-2026-57925 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags | ||
| CVE-2026-57923 | Med | 0.00 | 5.3 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings | ||
| CVE-2026-57922 | Low | 0.00 | 3.1 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible | ||
| CVE-2026-57921 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint | ||
| CVE-2026-1869 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the… |
- risk 0.00cvss 4.3epss 0.00
Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.
- risk 0.00cvss 5.8epss 0.00
Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.
- risk 0.00cvss 8.3epss 0.00
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.
- risk 0.00cvss 8.8epss 0.00
Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Syncee Premium Dropshipping & Wholesale <= 1.0.27 versions.
- risk 0.00cvss 7.3epss 0.00
Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Intranet & Private Site – All-In-One Intranet <= 1.8.1 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
- risk 0.00cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
- risk 0.00cvss 6.5epss 0.00
Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.
- risk 0.00cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
- risk 0.00cvss 5.3epss 0.00
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
- risk 0.00cvss 3.1epss 0.00
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
- risk 0.00cvss 4.3epss 0.00
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
- risk 0.00cvss 6.5epss 0.00
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the…