← Back
CWE-862

8,702 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,702)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Kdiskmark Project
2Fedora
Kdiskmark
Jun 17, 2026
Sep 14, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache.
1Google
1Android
Jun 17, 2026
Sep 9, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In network service, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Sep 9, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control vulnerability in Telecom application prior to SMR Sep-2022 Release 1 allows attacker to start emergency calls via undefined permission.
1Xwiki
1Xwiki
Jun 17, 2026
Sep 8, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature, string and list properties of objects the user shouldn't have access to can be accessed in versions...Show more
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature, string and list properties of objects the user shouldn't have access to can be accessed in versions prior to 13.10.4 and 14.2. This includes private personal information like email addresses and salted password hashes of registered users but also other information stored in properties of objects. Sensitive configuration fields like passwords for LDAP or SMTP servers could be accessed. By exploiting an additional vulnerability, this issue can even be exploited on private wikis at least for string properties. The issue is patched in version 13.10.4 and 14.2. Password properties are no longer displayed and rights are checked for other properties. A workaround is available. The template file `suggest.vm` can be replaced by a patched version without upgrading or restarting XWiki unless it has been overridden, in which case the overridden template should be patched, too. This might need adjustments for older versions, though.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Sep 7, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.10.11, 13.10.1, and 13.4.6, a bug in the security cache stores rules as...Show more
XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.10.11, 13.10.1, and 13.4.6, a bug in the security cache stores rules associated to document Page1.Page2 and space Page1.Page2 in the same cache entry. That means that it's possible to overwrite the rights of a space or a document by creating the page of the space with the same name and checking the right of the new one first so that they end up in the security cache and are used for the other too. The problem has been patched in XWiki 12.10.11, 13.10.1, and 13.4.6. There are no known workarounds.Show less
1Transposh
1Transposh Wordpress Translation
Jun 17, 2026
Sep 6, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking...Show more
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient permissions checking on the 'tp_translation' AJAX action and default settings which makes it possible for unauthenticated attackers to influence the data shown on the site.Show less
1Netic
1User Export For Jira
Jun 17, 2026
Sep 5, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoin...Show more
The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoint.Show less
1Wc Marketplace
1Multivendor Marketplace Solution For Woocommerce Wc Marketplace
Jun 17, 2026
Sep 5, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them a...Show more
The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in multiple AJAX actions, which could allow any authenticated users, such as subscriber to call them and suspend vendors (reporter by the submitter) or update arbitrary order status (identified by WPScan when verifying the issue) for example. Other unauthenticated attacks are also possible, either directly or via CSRFShow less
1Visualportfolio
1Visual Portfolio, Photo Gallery & Post Grid
Jun 17, 2026
Sep 5, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS...Show more
The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks in some of its REST endpoints, allowing unauthenticated users to call them and inject arbitrary CSS in arbitrary saved layoutsShow less
1Wpwax
1Directorist
Jun 17, 2026
Sep 5, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users
1Apache
1Iotdb
Jun 17, 2026
Sep 5, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue.
1Telosalliance
1Omnia Mpx Node Firmware
Jun 17, 2026
Sep 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control...Show more
A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of sensitive information which can be unlatched by exploiting the LFD vulnerability.Show less
1Nsqua
1Simply Schedule Appointments
Jun 17, 2026
Aug 29, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address
1Siteservercms Project
1Siteservercms
Jun 17, 2026
Aug 26, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx.
1Wwbn
1Avideo
Jun 17, 2026
Aug 22, 2022
N/A· v4
5.0 MEDIUM· v3
N/A· v2
Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request by an authenticated user can lead to unau...Show more
Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request by an authenticated user can lead to unauthorized access and takeover of resources. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Playlists plugin, allowing an attacker to bypass authentication by guessing a sequential ID, allowing them to take over the another user's playlists.Show less
1Wwbn
1Avideo
Jun 17, 2026
Aug 22, 2022
N/A· v4
4.2 MEDIUM· v3
N/A· v2
Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request by an authenticated user can lead to unau...Show more
Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request by an authenticated user can lead to unauthorized access and takeover of resources. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Live Schedules plugin, allowing an attacker to bypass authentication by guessing a sequential ID, allowing them to take over the another user's streams.Show less
1Awesomemotive
1Duplicator
Jun 17, 2026
Aug 22, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.
1Funnelkit
1Funnelkit Automations
Jun 17, 2026
Aug 22, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action, al...Show more
The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami WordPress plugin before 2.1.2 does not have authorisation and CSRF checks in one of its AJAX action, allowing any authenticated users, such as subscriber to create automationsShow less
1Shapedplugin
1Product Slider For Woocommerce
Jun 17, 2026
Aug 22, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in partic...Show more
The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber to call them. One in particular could allow them to delete arbitrary blog options.Show less
1Wpwax
1Directorist
Jun 17, 2026
Aug 22, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of the blog