Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 14/188
7.5
CVE-2026-57378

Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured

7.5
CVE-2026-57705

Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Acce

7.5
CVE-2026-57727

Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Secur

7.5
CVE-2026-57729

Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Contr

7.5
CVE-2026-62328

9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attack

7.5
CVE-2026-13765

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive

7.5
CVE-2026-11575

The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming paymen

7.5
CVE-2026-64622

Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/

7.5
CVE-2026-12082

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes

7.5
CVE-2026-59547

Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.

7.5
CVE-2026-61943

Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.

7.5
CVE-2026-61954

Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.

7.5
CVE-2026-65495

Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.

7.5
CVE-2026-65500

Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 ver

7.5
CVE-2026-59529

Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.

7.5
CVE-2026-59530

Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.

7.5
CVE-2026-59534

Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.

7.5
CVE-2026-59536

Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.

7.5
CVE-2026-66473

Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

7.5
CVE-2026-14924

The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in

7.5
CVE-2026-15025

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to

7.5
CVE-2026-54719

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.

7.5
CVE-2026-12500

The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a

7.5
CVE-2026-14930

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front

7.5
CVE-2026-16285

The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before str

7.5
CVE-2026-16561

The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX action

7.5
CVE-2026-12000

The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and

7.5
CVE-2026-6639

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all

7.5
CVE-2026-7529

The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and

7.5
CVE-2026-17613

Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated

7.5
CVE-2026-71316

Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries

7.5
CVE-2026-16734

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe p

7.5
CVE-2026-65551

Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Securit

7.5
CVE-2026-28140

Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.

7.5
CVE-2026-65504

Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.

7.5
CVE-2026-66712

Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.

7.5
CVE-2026-13399

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a

7.5
CVE-2026-70636

Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access th

7.5
CVE-2026-16041

The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST p

7.5
CVE-2026-72692

A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote att

7.5
CVE-2026-71962

Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants

7.5
CVE-2026-73249

calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{librar

7.5
CVE-2026-18789

The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality,

7.5
CVE-2026-27345

Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.

7.5
CVE-2026-61984

Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions.

7.5
CVE-2026-66431

Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions

7.5
CVE-2026-66441

Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.

7.5
CVE-2026-66461

Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.

7.5
CVE-2026-66466

Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checko

7.5
CVE-2026-66469

Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started