Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 96/188
4.3
CVE-2025-3843

A vulnerability was found in panhainan DS-Java 1.0. It has been classified as problematic. Affected is an unknown functi

4.3
CVE-2025-46232

Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configure

4.3
CVE-2024-12244

An issue has been discovered in access controls could allow users to view certain restricted project information even wh

4.3
CVE-2025-39385

Missing Authorization vulnerability in vowelweb Sirat sirat allows Exploiting Incorrectly Configured Access Control Secu

4.3
CVE-2025-46470

Missing Authorization vulnerability in Peter Raschendorfer Smart Hashtags [#hashtagger] hashtagger allows Exploiting Inc

4.3
CVE-2025-46519

Missing Authorization vulnerability in M.Code Media Library Downloader media-library-downloader allows Exploiting Incorr

4.3
CVE-2025-3915

The Aeropage Sync for Airtable plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabili

4.3
CVE-2025-3959

A vulnerability was found in withstars Books-Management-System 1.0. It has been declared as problematic. Affected by thi

4.3
CVE-2025-3964

A vulnerability, which was classified as problematic, was found in withstars Books-Management-System 1.0. Affected is an

4.3
CVE-2025-3977

A vulnerability was found in iteachyou Dreamer CMS up to 4.1.3. It has been declared as problematic. Affected by this vu

4.3
CVE-2025-3979

A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the fi

4.3
CVE-2025-3980

A vulnerability classified as problematic was found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. Thi

4.3
CVE-2025-3981

A vulnerability, which was classified as problematic, has been found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstatio

4.3
CVE-2025-3997

A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the fi

4.3
CVE-2025-3452

The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to unauthorized modification of data due to a

4.3
CVE-2025-39413

Missing Authorization vulnerability in David Gwyer Simple Sitemap – Create a Responsive HTML Sitemap simple-sitemap.This

4.3
CVE-2024-13420

Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on

4.3
CVE-2025-1326

The Homey theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th

4.3
CVE-2025-4282

A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. Th

4.3
CVE-2025-4327

A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is an unknown function. The ma

4.3
CVE-2025-47467

Missing Authorization vulnerability in GS Plugins GS Testimonial Slider gs-testimonial allows Exploiting Incorrectly Con

4.3
CVE-2025-47471

Missing Authorization vulnerability in EnvoThemes Envo Extra envo-extra allows Exploiting Incorrectly Configured Access

4.3
CVE-2025-47528

Missing Authorization vulnerability in pewilliams Ovation Elements ovation-elements allows Exploiting Incorrectly Config

4.3
CVE-2025-47591

Missing Authorization vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allows Exploiting Incorrectly C

4.3
CVE-2025-47692

Missing Authorization vulnerability in contentstudio Contentstudio contentstudio allows Exploiting Incorrectly Configure

4.3
CVE-2025-3949

The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for Wor

4.3
CVE-2025-4339

The TheGem theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t

4.3
CVE-2025-47887

Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers wit

4.3
CVE-2024-51666

Missing Authorization vulnerability in Tosin Oguntuyi Tours tours.This issue affects Tours: from n/a through <= 1.0.0.

4.3
CVE-2025-3624

Missing Authorization vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).T

4.3
CVE-2025-31063

Missing Authorization vulnerability in redqteam Wishlist wishlist allows Exploiting Incorrectly Configured Access Contro

4.3
CVE-2025-32295

Missing Authorization vulnerability in wordpresschef Salon Booking Pro salon-booking-plugin-pro-cc allows Exploiting Inc

4.3
CVE-2025-39482

Missing Authorization vulnerability in imithemes Eventer eventer allows Exploiting Incorrectly Configured Access Control

4.3
CVE-2025-39493

Missing Authorization vulnerability in ValvePress Rankie valvepress-rankie allows Exploiting Incorrectly Configured Acce

4.3
CVE-2025-39511

Missing Authorization vulnerability in ValvePress Pinterest Automatic Pin wp-pinterest-automatic allows Exploiting Incor

4.3
CVE-2025-47534

Missing Authorization vulnerability in ValvePress Wordpress Auto Spinner wp-auto-spinner allows Exploiting Incorrectly C

4.3
CVE-2025-48079

Missing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Ex

4.3
CVE-2025-48128

Missing Authorization vulnerability in Sharespine Sharespine Woocommerce Connector sharespine-woocommerce-connector allo

4.3
CVE-2025-48138

Missing Authorization vulnerability in Bertha AI – Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly

4.3
CVE-2025-4887

A vulnerability, which was classified as problematic, has been found in SourceCodester Online Student Clearance System 1

4.3
CVE-2025-48247

Missing Authorization vulnerability in Blair Williams Shortlinks by Pretty Links pretty-link allows Exploiting Incorrect

4.3
CVE-2025-48260

Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting I

4.3
CVE-2025-48262

Missing Authorization vulnerability in M.Code Url Rewrite Analyzer url-rewrite-analyzer allows Exploiting Incorrectly Co

4.3
CVE-2025-48268

Missing Authorization vulnerability in Guru Team Bot for Telegram on WooCommerce bot-for-telegram-on-woocommerce allows

4.3
CVE-2025-39376

Missing Authorization vulnerability in QuanticaLabs Car Park Booking System for WordPress car-park-booking-system-for-wo

4.3
CVE-2025-39398

Missing Authorization vulnerability in Themovation Bellevue bellevuex.This issue affects Bellevue: from n/a through <= 4

4.3
CVE-2025-39412

Missing Authorization vulnerability in averta Master Slider master-slider.This issue affects Master Slider: from n/a thr

4.3
CVE-2025-39454

Missing Authorization vulnerability in Jeroen Peters Name Directory name-directory.This issue affects Name Directory: fr

4.3
CVE-2025-5033

A vulnerability classified as problematic was found in XiaoBingby TeaCMS 2.0.2. Affected by this vulnerability is an unk

4.3
CVE-2025-5132

A vulnerability was found in Tmall Demo up to 20250505. It has been rated as problematic. This issue affects some unknow

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started