VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,244)

page 141 of 213
  • CVE-2026-3210MedMar 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect Authorization vulnerability in Drupal Material Icons allows Forceful Browsing.This issue affects Material Icons: from 0.0.0 before 2.0.4.

  • CVE-2026-21286MedMar 11, 2026
    risk 0.34cvss 5.3epss 0.00

    Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security…

  • CVE-2026-31838MedMar 10, 2026
    risk 0.34cvss 5.3epss 0.00

    Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerability in Envoy RBAC header matching could allow authorization policy bypass when policies rely on HTTP headers that may contain multiple values. An attacker…

  • CVE-2026-2126MedFeb 18, 2026
    risk 0.34cvss 5.3epss 0.00

    The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 20260113. This is due to the `usp_get_submitted_category()` function accepting user-submitted category…

  • CVE-2026-21722MedFeb 12, 2026
    risk 0.34cvss 5.3epss 0.00

    Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did…

  • CVE-2026-26031MedFeb 11, 2026
    risk 0.34cvss 5.3epss 0.00

    Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identified in Frappe Learning, where unauthorised users were able to access the full list of enrolled students (by email) in batches. This…

  • CVE-2026-1734MedFeb 2, 2026
    risk 0.34cvss 5.3epss 0.01

    A security flaw has been discovered in Zhong Bang CRMEB up to 5.6.3. This vulnerability affects unknown code of the file crmeb/app/api/controller/v1/CrontabController.php of the component crontab Endpoint. The manipulation results in missing authorization. The attack can be…

  • CVE-2025-15525MedJan 31, 2026
    risk 0.34cvss 5.3epss 0.00

    The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect authorization on the parse_custom_args() function in all versions up to, and including, 7.8.1. This makes it possible for…

  • CVE-2025-13985MedJan 28, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect Authorization vulnerability in Drupal Entity Share allows Forceful Browsing.This issue affects Entity Share: from 0.0.0 before 3.13.0.

  • CVE-2026-23961MedJan 22, 2026
    risk 0.34cvss 5.3epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to suspend remote users to prevent interactions. However, some logic errors allow already-known posts from such suspended users to appear in timelines if boosted.…

  • CVE-2025-15513MedJan 14, 2026
    risk 0.34cvss 5.3epss 0.00

    The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error handling in the verifyFloatResponse() function in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to mark any…

  • CVE-2025-14352MedJan 7, 2026
    risk 0.34cvss 5.3epss 0.00

    The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect authorization in the room-single.php shortcode handler in all versions up to, and including, 1.0.3. This is due to the plugin relying solely on nonce verification…

  • CVE-2025-9056MedDec 10, 2025
    risk 0.34cvss 5.3epss 0.00

    Unprotected service in the AudioLink component allows a local attacker to overwrite system files via unauthorized service invocation.

  • CVE-2025-64753MedNov 13, 2025
    risk 0.34cvss 5.3epss 0.00

    grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document could still access endpoints listing hashes for versions of that document and receive a full list of changes between versions, even if those changes contained…

  • CVE-2025-11581MedOct 10, 2025
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file /openApi/runJob of the component OpenAPIController. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit has been…

  • CVE-2025-54877MedAug 29, 2025
    risk 0.34cvss 5.3epss 0.00

    Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition versions before 16.10.99.1754050155 and Tuleap Enterprise Edition versions before 16.9-8 and before 16.10-5, an attacker can access to the…

  • CVE-2025-54554MedAug 4, 2025
    risk 0.34cvss 5.3epss 0.00

    tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that reveal sensitive information about the underlying SQL queries and database structure.

  • CVE-2025-6003MedJun 12, 2025
    risk 0.34cvss 5.3epss 0.00

    The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capability check on a function in all versions up to, and including, the *.5.3 versions of the plugin. This makes it possible for unauthenticated attackers to…

  • CVE-2025-3609MedMay 6, 2025
    risk 0.34cvss 5.3epss 0.00

    The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 2.1.2. This is due to the 'reales_user_signup_form' AJAX action not verifying if user registration is enabled, prior to registering a user. This makes it…

  • CVE-2025-43921MedApr 20, 2025
    risk 0.34cvss 5.3epss 0.00

    GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.