CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,268)
page 75 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-19539 | Hig | 0.49 | — | 0.00 | Aug 11, 2026 | Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content (title, description, and attachments) of tickets belonging to another company, to… | ||
| CVE-2026-71962 | Hig | 0.49 | 7.5 | 0.00 | Aug 10, 2026 | Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attackers to access private files by exploiting the endpoint's inclusion in the global authentication… | ||
| CVE-2026-72692 | Hig | 0.49 | 7.5 | 0.00 | Aug 10, 2026 | A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline any in-flight document and forge the decline attribution to an arbitrary user via the declinedoc Parse cloud function. The… | ||
| CVE-2026-16041 | Hig | 0.49 | 7.5 | 0.00 | Aug 7, 2026 | The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star… | ||
| CVE-2026-70636 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in… | ||
| CVE-2026-67621 | Hig | 0.49 | 7.6 | 0.00 | Aug 6, 2026 | Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP… | ||
| CVE-2026-13399 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments | ||
| CVE-2026-66712 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions. | ||
| CVE-2026-65504 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions. | ||
| CVE-2026-28140 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. | ||
| CVE-2026-65551 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Breakdance: from n/a before 2.7. | ||
| CVE-2026-16734 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every… | ||
| CVE-2026-17613 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2026 | Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning. | ||
| CVE-2026-7529 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2026 | The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoints being registered with `permission_callback => '__return_true'` in all versions up to, and… | ||
| CVE-2026-6639 | Hig | 0.49 | 7.5 | 0.00 | Aug 5, 2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6. This is due to the `getCurrentTaskResults()` method in `modules/workspace/controller.php` being accessible without… | ||
| CVE-2026-12000 | Hig | 0.49 | 7.5 | 0.01 | Aug 5, 2026 | The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0 via the WordPress core REST endpoints /wp-json/wp/v2/pages, /wp-json/wp/v2/pages/, /wp-json/wp/v2/posts, and /wp-json/wp/v2/posts/.… | ||
| CVE-2026-68587 | Hig | 0.49 | 8.6 | 0.00 | Aug 3, 2026 | SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. Anonymous readers or publish… | ||
| CVE-2026-68586 | Hig | 0.49 | 8.6 | 0.00 | Aug 3, 2026 | SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the corresponding backlink list endpoints filter publish-forbidden documents, the content… | ||
| CVE-2026-9178 | Hig | 0.49 | 7.5 | 0.00 | Jun 24, 2026 | The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/list/ (callback userDetail()) with permission_callback set to '__return_true', and the function's… | ||
| CVE-2026-56341 | Hig | 0.49 | 7.5 | 0.00 | Jun 20, 2026 | AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPal tokens, Authorize.Net webhooks, and Bitcoin transaction records. Unauthenticated attackers can retrieve all payment transaction… |
- risk 0.49cvss —epss 0.00
Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content (title, description, and attachments) of tickets belonging to another company, to…
- risk 0.49cvss 7.5epss 0.00
Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attackers to access private files by exploiting the endpoint's inclusion in the global authentication…
- risk 0.49cvss 7.5epss 0.00
A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline any in-flight document and forge the decline attribution to an arbitrary user via the declinedoc Parse cloud function. The…
- risk 0.49cvss 7.5epss 0.00
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star…
- risk 0.49cvss 7.5epss 0.00
Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in…
- risk 0.49cvss 7.6epss 0.00
Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP…
- risk 0.49cvss 7.5epss 0.00
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
- risk 0.49cvss 7.5epss 0.00
Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Breakdance: from n/a before 2.7.
- risk 0.49cvss 7.5epss 0.00
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every…
- risk 0.49cvss 7.5epss 0.00
Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.
- risk 0.49cvss 7.5epss 0.00
The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoints being registered with `permission_callback => '__return_true'` in all versions up to, and…
- risk 0.49cvss 7.5epss 0.00
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6. This is due to the `getCurrentTaskResults()` method in `modules/workspace/controller.php` being accessible without…
- risk 0.49cvss 7.5epss 0.01
The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0 via the WordPress core REST endpoints /wp-json/wp/v2/pages, /wp-json/wp/v2/pages/, /wp-json/wp/v2/posts, and /wp-json/wp/v2/posts/.…
- risk 0.49cvss 8.6epss 0.00
SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. Anonymous readers or publish…
- risk 0.49cvss 8.6epss 0.00
SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the corresponding backlink list endpoints filter publish-forbidden documents, the content…
- risk 0.49cvss 7.5epss 0.00
The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/list/ (callback userDetail()) with permission_callback set to '__return_true', and the function's…
- risk 0.49cvss 7.5epss 0.00
AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPal tokens, Authorize.Net webhooks, and Bitcoin transaction records. Unauthenticated attackers can retrieve all payment transaction…