Vulnerabilities (CVE)

Filtered by CWE-862
Total 4572 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-3561 2025-04-14 N/A 4.3 MEDIUM
A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2022-45826 1 Sunshinephotocart 1 Sunshine Photo Cart 2025-04-11 N/A 5.4 MEDIUM
Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through 2.9.13.
CVE-2022-45819 1 Code-atlantic 1 Popup Maker 2025-04-11 N/A 3.5 LOW
Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Maker: from n/a through 1.17.1.
CVE-2022-47594 1 Wpdeveloper 1 Essential Blocks 2025-04-11 N/A 6.5 MEDIUM
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through 3.8.5.
CVE-2021-35001 1 Bmc 1 Track-it\! 2025-04-11 N/A 6.5 MEDIUM
BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It!. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetData endpoint. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-14527.
CVE-2025-32220 1 Salonbookingsystem 1 Salon Booking System 2025-04-11 N/A 8.8 HIGH
Missing Authorization vulnerability in Dimitri Grassi Salon booking system allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Salon booking system: from n/a through 10.10.7.
CVE-2025-32542 2025-04-11 N/A N/A
Missing Authorization vulnerability in EazyPlugins Eazy Plugin Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Eazy Plugin Manager: from n/a through 4.3.0.
CVE-2025-31041 2025-04-11 N/A N/A
Missing Authorization vulnerability in NotFound AnyTrack Affiliate Link Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AnyTrack Affiliate Link Manager: from n/a through 1.0.4.
CVE-2024-7031 1 Ninjateam 1 Filester 2025-04-10 N/A 8.8 HIGH
The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' function in all versions up to, and including, 1.8.2. This makes it possible for authenticated attackers, with a role that has been granted permissions by an Administrator, to update the plugin settings for user role restrictions, including allowing file types such as .php to be uploaded.
CVE-2025-26378 1 Q-free 1 Maxtime 2025-04-10 N/A 8.8 HIGH
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to reset passwords, including the ones of administrator accounts, via crafted HTTP requests.
CVE-2025-26367 1 Q-free 1 Maxtime 2025-04-10 N/A 4.3 MEDIUM
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to create arbitrary user groups via crafted HTTP requests.
CVE-2025-26371 1 Q-free 1 Maxtime 2025-04-10 N/A 8.8 HIGH
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to add users to groups via crafted HTTP requests.
CVE-2025-26376 1 Q-free 1 Maxtime 2025-04-10 N/A 6.5 MEDIUM
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to modify user data via crafted HTTP requests.
CVE-2024-33914 1 Exclusiveaddons 1 Exclusive Addons For Elementor 2025-04-10 N/A 9.8 CRITICAL
Missing Authorization vulnerability in Exclusive Addons Exclusive Addons Elementor.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.1.
CVE-2022-3911 1 Iubenda 1 Iubenda-cookie-law-solution 2025-04-10 N/A 8.8 HIGH
The iubenda WordPress plugin before 3.3.3 does does not have authorisation and CSRF in an AJAX action, and does not ensure that the options to be updated belong to the plugin as long as they are arrays. As a result, any authenticated users, such as subscriber can grant themselves any privileges, such as edit_plugins etc
CVE-2022-44437 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-04-10 N/A 5.5 MEDIUM
In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.
CVE-2025-26375 1 Q-free 1 Maxtime 2025-04-10 N/A 8.8 HIGH
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to create users with arbitrary privileges via crafted HTTP requests.
CVE-2025-26368 1 Q-free 1 Maxtime 2025-04-10 N/A 8.1 HIGH
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove user groups via crafted HTTP requests.
CVE-2025-26871 1 Wpdeveloper 1 Essential Blocks 2025-04-10 N/A 8.8 HIGH
Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Essential Blocks for Gutenberg: from n/a through 4.8.3.
CVE-2022-38682 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-04-10 N/A 5.5 MEDIUM
In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.