CWE-862
8,681 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,681)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to access memory entries without proper authorization. Attackers can skip sessi...Show more |
A denial-of-service vulnerability exists in NPort devices because of improper access control on the command port. The command interface does not properly validate whether a sender is associated with a valid data port ses...Show more |
A security issue was identified in Pavilion due to improper authorization enforcement in API endpoints. This vulnerability can allow an unauthorized actor to execute privileged operations, including user/role management...Show more |
Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions. |
Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions. |
Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions. |
Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Metro Magazine: from n/a through 1.4.1. |
Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions. |
The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including...Show more |
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions. |
The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due to a missing capability check and missing nonce validation in the...Show more |
The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to the plugin not properly verifying that a user is authorized to perfo...Show more |
Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions. |
Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions. |
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions. |
Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions. |
Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions. |
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions. |
Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions. |
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions. |