← Back
CWE-862

9,590 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (9,590)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jul 14, 2026
Jul 2, 2026
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by exploiting unprotected POST endpoints on the user-story...Show more
Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by exploiting unprotected POST endpoints on the user-story, task, and issue due-date API viewsets. Attackers can supply an arbitrary project identifier to these endpoints, which bypass permission checks and apply the AllowAny default, to pre-empt project administrators from initializing due dates by creating records before they can do so themselves.Show less
-
-
Jul 2, 2026
Jul 2, 2026
4.9 MEDIUM· v4
N/A· v3
N/A· v2
Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above prior to 4.17.14 contain an authorization issue where a forced folder move can delete a confl...Show more
Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above prior to 4.17.14 contain an authorization issue where a forced folder move can delete a conflicting destination folder without destination delete permission. Function craft\\controllers\\AssetsController::actionMoveFolder() supports moving an asset folder into a destination parent folder. If a folder with the same name already exists at the destination, the action can be called with force=true to overwrite the destination. This issue has been resolved in versions 5.9.21 and 4.17.14.Show less
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29.
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Subscriber Broken Access Control in Booked <= 3.0.0 versions.
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Contributor Broken Access Control in Flatsome <= 3.20.5 versions.
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
8.2 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions.
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions.
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is aut...Show more
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve every distinct value stored under any arbitrary wp_postmeta key on the site — including WooCommerce billing PII such as _billing_email, _billing_phone, and _billing_address fields, order totals, attachment paths, and any third-party plugin credentials or tokens stored in post meta — provided at least one published JetFormBuilder form with a get_from_db generator field exists on the site. Exploitation requires that the target site has at least one published jet-form-builder post containing a field whose generator_function is set to get_from_db; an attacker must supply a matching form ID, field name, and generator ID in the request, but all of these can be discovered by browsing the site's public forms.Show less
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.11. This is due to the plugin not properly verifying th...Show more
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to send arbitrary HTML-injected emails — including phishing messages embedding a real, valid WordPress password-reset URL for the targeted user — to any registered user via the site's own mail server, abusing its SPF/DKIM reputation. The attacker-controlled emailSubject parameter is passed to wp_mail() with only sanitize_text_field() applied, while emailBody 'text' items are concatenated raw into the HTML email body with no escaping, and 'chip' items can include the genuine WordPress password-reset link for the targeted account.Show less
-
-
Jul 2, 2026
Jul 2, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.7.8. This is due to the plugin not properly verifying...Show more
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.7.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary season groups or modify existing group names, participants, and round-type options. Exploitation requires obtaining the joomsportajaxnonce, which is exposed on frontend pages that render a JoomSport shortcode.Show less