Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 138/188
4.3
CVE-2024-5997

The Duplica – Duplicate Posts, Pages, Custom Posts or Users plugin for WordPress is vulnerable to unauthorized modificat

4.3
CVE-2024-6799

The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to

4.3
CVE-2024-6491

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c

4.3
CVE-2024-6836

The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps

4.3
CVE-2024-1804

The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing

4.3
CVE-2024-37898

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has

4.3
CVE-2024-5331

The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1

4.3
CVE-2024-6709

The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c

4.3
CVE-2024-6872

The Build Your Dream Website Fast with 400+ Starter Templates and Landing Pages, No Coding Needed, One-Click Import for

4.3
CVE-2024-6987

The Orchid Store theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec

4.3
CVE-2024-6824

The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to

4.3
CVE-2024-7648

The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl

4.3
CVE-2024-42377

SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which wi

4.3
CVE-2024-39591

SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escala

4.3
CVE-2024-41734

Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker

4.3
CVE-2024-42373

SAP Student Life Cycle Management (SLcM) fails to conduct proper authorization checks for authenticated users, leading t

4.3
CVE-2024-6883

The Event Espresso 4 Decaf – Event Registration Event Ticketing plugin for WordPress is vulnerable to limited unauthoriz

4.3
CVE-2024-7030

The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized modification of data due to a missi

4.3
CVE-2024-6688

The Oxygen Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c

4.3
CVE-2024-8199

The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for Wor

4.3
CVE-2024-7380

The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability c

4.3
CVE-2024-7605

The HelloAsso plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check

4.3
CVE-2024-44082

In OpenStack Ironic before 26.0.1 and ironic-python-agent before 9.13.1, there is a vulnerability in image processing, i

4.3
CVE-2024-8427

The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unau

4.3
CVE-2024-7622

The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing cap

4.3
CVE-2024-41729

Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the ne

4.3
CVE-2024-42380

The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along

4.3
CVE-2024-44113

Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access in

4.3
CVE-2024-44115

The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulner

4.3
CVE-2024-44116

The RFC enabled function module allows a low privileged user to add any workbook to any user's workplace favourites. Thi

4.3
CVE-2024-44112

Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as

4.3
CVE-2024-7721

The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modificati

4.3
CVE-2024-8432

The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modif

4.3
CVE-2024-8437

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missin

4.3
CVE-2024-8434

The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a m

4.3
CVE-2024-47330

Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This i

4.3
CVE-2024-8552

The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability

4.3
CVE-2024-47337

Missing Authorization vulnerability in Phillip Dane Joy Of Text Lite joy-of-text.This issue affects Joy Of Text Lite: fr

4.3
CVE-2024-8771

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f

4.3
CVE-2024-8675

The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che

4.3
CVE-2024-8431

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data

4.3
CVE-2024-9685

The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing c

4.3
CVE-2024-9067

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress

4.3
CVE-2024-9187

The Read more By Adam plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check

4.3
CVE-2024-9824

The ImagePress – Image Gallery plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a

4.3
CVE-2024-9756

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads

4.3
CVE-2024-9891

The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due

4.3
CVE-2023-7290

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a

4.3
CVE-2023-7292

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal

4.3
CVE-2023-7293

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started