← Back
CWE-862

8,683 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,683)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Storeapps
1Temporary Login Without Password
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when updating its settings, which could allows any logged-in users, such as subscribers to update them
1Contact Form Advanced Database Project
1Contact Form Advanced Database
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, whic...Show more
The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead to arbitrary metadata deletion, as well as PHP Object Injection if a suitable gadget chain is present in another plugin, as user data is passed to the maybe_unserialize() function without being first validated.Show less
1Advancedcustomfields
1Advanced Custom Fields
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to move the unauthorized...Show more
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to move the unauthorized field group via unspecified vectors.Show less
1Advancedcustomfields
1Advanced Custom Fields
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to obtain the unauthoriz...Show more
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to obtain the unauthorized information via unspecified vectors.Show less
1Advancedcustomfields
1Advanced Custom Fields
Jun 17, 2026
Dec 13, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may allow a user to browse unauthorized data vi...Show more
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may allow a user to browse unauthorized data via unspecified vectors.Show less
1Snipeitapp
1Snipe It
Jun 17, 2026
Dec 10, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
snipe-it is vulnerable to Improper Access Control
1Google
1Android
Jun 17, 2026
Dec 8, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without permission.
1Inveniosoftware
1Invenio Drafts Resources
Jun 17, 2026
Dec 6, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions whe...Show more
Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable in a default installation of InvenioRDM. An authenticated a user is able via REST API calls to publish draft records of other users if they know the record identifier and the draft validates (e.g. all require fields filled out). An attacker is not able to modify the data in the record, and thus e.g. *cannot* change a record from restricted to public. The problem is patched in Invenio-Drafts-Resources v0.13.7 and 0.14.6, which is part of InvenioRDM v6.0.1 and InvenioRDM v7.0 respectively.Show less
1Tawk
1Tawk.to Live Chat
Jun 17, 2026
Dec 6, 2021
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX actions, available to any authenticated user. The first one allows low-pri...Show more
The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and tawkto_removewidget AJAX actions, available to any authenticated user. The first one allows low-privileged users (including simple subscribers) to change the 'tawkto-embed-widget-page-id' and 'tawkto-embed-widget-widget-id' parameters. Any authenticated user can thus link the vulnerable website to their own Tawk.to instance. Consequently, they will be able to monitor the vulnerable website and interact with its visitors (receive contact messages, answer, ...). They will also be able to display an arbitrary Knowledge Base. The second one will remove the live chat widget from pages.Show less
1Chamilo
1Chamilo Lms
Jun 17, 2026
Dec 3, 2021
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.
1Bulk Datetime Change Project
1Bulk Datetime Change
Jun 17, 2026
Nov 29, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other user...Show more
The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.Show less
1Wpwave
1Hide My Wp
Jun 17, 2026
Nov 24, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.
1Mercari
1Mercari
Jun 17, 2026
Nov 24, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper authorization in handler for custom URL scheme vulnerability in Android App 'Mercari (Merpay) - Marketplace and Mobile Payments App' (Japan version) versions prior to 4.49.1 allows a remote attacker to lead a us...Show more
Improper authorization in handler for custom URL scheme vulnerability in Android App 'Mercari (Merpay) - Marketplace and Mobile Payments App' (Japan version) versions prior to 4.49.1 allows a remote attacker to lead a user to access an arbitrary website and the website launches an arbitrary Activity of the app via the vulnerable App, which may result in Mercari account's access token being obtained.Show less
1Apache
1Ozone
Jun 17, 2026
Nov 19, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user.
1Apache
1Ozone
Jun 17, 2026
Nov 19, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, not just by admins.
1Apache
1Ozone
Jun 17, 2026
Nov 19, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify R...Show more
In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify Ratis replication configuration.Show less
1Webfactoryltd
1Wp Reset Pro
Jun 17, 2026
Nov 18, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete w...Show more
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and takeover.Show less
1Google
1Android
Jun 17, 2026
Nov 18, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In Browser app, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed...Show more
In Browser app, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-199678035Show less
1Insert Pages Project
1Insert Pages
Jun 17, 2026
Nov 17, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and metadata from arbitrary posts/pages regardless of their author and status (ie private), using a shortcod...Show more
The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and metadata from arbitrary posts/pages regardless of their author and status (ie private), using a shortcode. Password protected posts/pages are not affected by such issue.Show less
1Sap
1Erp Human Capital Management
Jun 17, 2026
Nov 10, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
SAP ERP HCM Portugal does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll information, the attacker can...Show more
SAP ERP HCM Portugal does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll information, the attacker can neither modify any information nor cause availability impacts.Show less