CWE-862
10,102 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (10,102)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. This issue has been patched in version 1.6.4. There are currently no known workarounds. |
The Mediamatic – Media Library Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX actions in versions up to, and including, 2.8.1. This makes it possible for...Show more |
Flarum is a discussion platform for websites. If the first post of a discussion is permanently deleted but the discussion stays visible, any actor who can view the discussion is able to create a new reply via the REST AP...Show more |
Flarum is a forum software for building communities. Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending com...Show more |
1Royal Elementor Addons 1Royal Elementor Addons Jun 17, 2026 Jan 9, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated...Show more |
1Royal Elementor Addons 1Royal Elementor Addons Jun 17, 2026 Jan 9, 2023 N/A· v4 3.1 LOW· v3 N/A· v2 The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and does not ensure that the post to be deleted is a template. This could allow any authentic...Show more |
1Activecampaign 1Activecampaign For Woocommerce Jun 17, 2026 Jan 9, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its error logs via an AJAX action, which could allow any authenticated users, such as subscriber to call...Show more |
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed. |
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed. |
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed. |
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed. |
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed. |
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed. |
In music service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed. |
In music service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed. |
In music service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed. |
In contacts service, there is a missing permission check. This could lead to local denial of service in Contacts service with no additional execution privileges needed. |
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. |
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. |
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. |