VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 75 of 464
  • CVE-2026-19539HigAug 11, 2026
    risk 0.49cvss epss 0.00

    Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content (title, description, and attachments) of tickets belonging to another company, to…

  • CVE-2026-71962HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.00

    Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attackers to access private files by exploiting the endpoint's inclusion in the global authentication…

  • CVE-2026-72692HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.00

    A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline any in-flight document and forge the decline attribution to an arbitrary user via the declinedoc Parse cloud function. The…

  • CVE-2026-16041HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star…

  • CVE-2026-70636HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in…

  • CVE-2026-67621HigAug 6, 2026
    risk 0.49cvss 7.6epss 0.00

    Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP…

  • CVE-2026-13399HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments

  • CVE-2026-66712HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.

  • CVE-2026-65504HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.

  • CVE-2026-28140HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.

  • CVE-2026-65551HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Breakdance: from n/a before 2.7.

  • CVE-2026-16734HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every…

  • CVE-2026-17613HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.

  • CVE-2026-7529HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoints being registered with `permission_callback => '__return_true'` in all versions up to, and…

  • CVE-2026-6639HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6. This is due to the `getCurrentTaskResults()` method in `modules/workspace/controller.php` being accessible without…

  • CVE-2026-12000HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.01

    The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0 via the WordPress core REST endpoints /wp-json/wp/v2/pages, /wp-json/wp/v2/pages/, /wp-json/wp/v2/posts, and /wp-json/wp/v2/posts/.…

  • CVE-2026-68587HigAug 3, 2026
    risk 0.49cvss 8.6epss 0.00

    SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. Anonymous readers or publish…

  • CVE-2026-68586HigAug 3, 2026
    risk 0.49cvss 8.6epss 0.00

    SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the corresponding backlink list endpoints filter publish-forbidden documents, the content…

  • CVE-2026-9178HigJun 24, 2026
    risk 0.49cvss 7.5epss 0.00

    The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/list/ (callback userDetail()) with permission_callback set to '__return_true', and the function's…

  • CVE-2026-56341HigJun 20, 2026
    risk 0.49cvss 7.5epss 0.00

    AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPal tokens, Authorize.Net webhooks, and Bitcoin transaction records. Unauthenticated attackers can retrieve all payment transaction…