Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-266

MITRE ↗

CWE-266

56
CRITICAL
134
HIGH
235
MEDIUM
14
LOW
446 CVEs · Page 1/9
10.0
CVE-2026-23800

Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affe

9.9
CVE-2026-22907

An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system dat

9.9
CVE-2026-32922

OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with

9.9
CVE-2026-42368

A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A spec

9.8
CVE-2026-23550

Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This

9.8
CVE-2025-68869

Incorrect Privilege Assignment vulnerability in LazyCoders LLC LazyTasks lazytasks-project-task-management allows Privil

9.8
CVE-2026-27983

Incorrect Privilege Assignment vulnerability in designthemes LMS Elementor Pro lms-elementor-pro allows Privilege Escala

9.8
CVE-2026-27542

Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wh

9.8
CVE-2026-24968

Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue aff

9.8
CVE-2026-24971

Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issu

9.8
CVE-2026-27051

Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: fro

9.8
CVE-2026-32520

Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalati

9.8
CVE-2026-33518

An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows h

9.8
CVE-2026-33519

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kube

9.8
CVE-2026-22337

Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This is

9.8
CVE-2026-48172 KEV

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild i

9.8
CVE-2026-42731

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allow

9.8
CVE-2026-42758

Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privile

9.8
CVE-2026-42680

Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows P

9.8
CVE-2026-48879

Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from

9.8
CVE-2025-53209

Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue aff

9.8
CVE-2026-49060

Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This iss

9.8
CVE-2026-34901

Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.

9.8
CVE-2026-39583

Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.

9.8
CVE-2025-69179

Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions.

9.8
CVE-2026-27395

Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.

9.8
CVE-2026-49058

Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.

9.8
CVE-2026-54807

Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.

9.8
CVE-2026-56028

Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website Templates <= 1.4.9 vers

9.8
CVE-2026-56030

Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.

9.8
CVE-2026-56033

Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.

9.8
CVE-2026-57692

Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects Pr

9.8
CVE-2026-57813

Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issu

9.8
CVE-2026-59540

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.

9.8
CVE-2026-61951

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.

9.8
CVE-2026-65507

Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.

9.8
CVE-2026-66662

Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.

9.8
CVE-2026-66424

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.

9.8
CVE-2026-72839

filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default Cr

9.8
CVE-2026-73347

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.

9.8
CVE-2026-73390

Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.

9.8
CVE-2025-15689

Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.

9.8
CVE-2026-66682

Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

9.8
CVE-2026-28165

Unauthenticated Privilege Escalation in Digits <= 9.2 versions.

9.8
CVE-2026-32558

Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.

9.8
CVE-2026-66648

Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.

9.8
CVE-2026-78267

Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.

9.8
CVE-2026-78477

The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This mak

9.8
CVE-2026-32566

Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

9.6
CVE-2026-12294

Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox E

Frequently Asked Questions

What is CWE-266?

CWE-266 (CWE-266) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-266?

There are 447 CVE records associated with CWE-266 in our database. Of these, 56 are critical severity, 134 are high severity, and 235 are medium severity.

How can I protect against CWE-266 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-266 using AI-powered security agents.

Detect CWE-266 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-266 vulnerabilities across your infrastructure.

Get Started