CWE-862
9,590 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (9,590)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to the plugin not properly verifying that a user is authorized to perfo...Show more |
Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions. |
Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions. |
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions. |
Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions. |
Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions. |
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions. |
Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions. |
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions. |
OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, The ValidateArgumentType RPC endpoint in service/internal/api/api.go does not perform any authentication or authori...Show more |
Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions. |
Unauthenticated Broken Access Control in AI Product Search for WooCommerce – Motive Commerce Search <= 1.38.2 versions. |
Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions. |
Subscriber Broken Access Control in Classified Listing <= 5.3.9 versions. |
Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions. |
Subscriber Broken Access Control in Amelia <= 2.2 versions. |
Subscriber Broken Access Control in myCred <= 3.0.3 versions. |
Subscriber Broken Access Control in Groundhogg < 4.4.1 versions. |
Subscriber Broken Access Control in ChatBot <= 7.9.7 versions. |
Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions. |