Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 97/188
4.3
CVE-2025-5185

A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. It has been declared as

4.3
CVE-2025-4683

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modifi

4.3
CVE-2024-47055

SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vul

4.3
CVE-2025-4431

The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to unauthorized modificatio

4.3
CVE-2025-5410

A vulnerability was found in Mist Community Edition up to 4.7.1. It has been declared as problematic. This vulnerability

4.3
CVE-2025-4047

The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check

4.3
CVE-2025-5521

A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulne

4.3
CVE-2025-1778

The Art Theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'arttheme_them

4.3
CVE-2025-5732

A vulnerability, which was classified as problematic, was found in code-projects Traffic Offense Reporting System 1.0. T

4.3
CVE-2023-26002

Missing Authorization vulnerability in 6Storage 6Storage Rentals allows Exploiting Incorrectly Configured Access Control

4.3
CVE-2025-28994

Missing Authorization vulnerability in viralloops Viral Loops WP Integration viral-loops-wp-integration allows Exploitin

4.3
CVE-2025-28996

Missing Authorization vulnerability in Thad Allender GPP Slideshow gpp-slideshow allows Exploiting Incorrectly Configure

4.3
CVE-2025-29010

Missing Authorization vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powered-by-behance allows Ex

4.3
CVE-2025-30624

Missing Authorization vulnerability in WordLift WordLift wordlift allows Exploiting Incorrectly Configured Access Contro

4.3
CVE-2025-30927

Missing Authorization vulnerability in Wordapp Team Wordapp wordapp allows Exploiting Incorrectly Configured Access Cont

4.3
CVE-2025-30974

Missing Authorization vulnerability in Akhtarujjaman Shuvo Post Grid Master ajax-filter-posts allows Exploiting Incorrec

4.3
CVE-2025-30978

Missing Authorization vulnerability in Dor Zuberi Slack Notifications by dorzki dorzki-notifications-to-slack allows Exp

4.3
CVE-2025-30990

Missing Authorization vulnerability in ThemeHunk ThemeHunk themehunk-megamenu-plus allows Exploiting Incorrectly Configu

4.3
CVE-2025-49240

Missing Authorization vulnerability in nK DocsPress docspress allows Exploiting Incorrectly Configured Access Control Se

4.3
CVE-2025-49246

Missing Authorization vulnerability in cmoreira Testimonials Showcase testimonials-showcase allows Exploiting Incorrectl

4.3
CVE-2025-49248

Missing Authorization vulnerability in cmoreira Team Showcase team-showcase-cm allows Exploiting Incorrectly Configured

4.3
CVE-2025-49272

Missing Authorization vulnerability in sergiotrinity Trinity Audio trinity-audio allows Exploiting Incorrectly Configure

4.3
CVE-2025-49287

Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Exploiting I

4.3
CVE-2025-49293

Missing Authorization vulnerability in CodeRevolution Crawlomatic Multisite Scraper Post Generator crawlomatic-multipage

4.3
CVE-2025-5766

A vulnerability was found in code-projects Laundry System 1.0. It has been declared as problematic. This vulnerability a

4.3
CVE-2025-5885

A vulnerability has been found in Konica Minolta bizhub up to 20250202 and classified as problematic. This vulnerability

4.3
CVE-2025-5888

A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been declared as problematic. Affected by this vulnerabili

4.3
CVE-2025-5900

A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part.

4.3
CVE-2025-42987

SAP Manage Processing Rules (For Bank Statement) allows an attacker with basic privileges to edit shared rules of any us

4.3
CVE-2025-42991

SAP S/4HANA (Bank Account Application) does not perform necessary authorization checks. This allows an authenticated 'ap

4.3
CVE-2025-6105

A vulnerability has been found in jflyfox jfinal_cms 5.0.1 and classified as problematic. This vulnerability affects unk

4.3
CVE-2025-6106

A vulnerability was found in WuKongOpenSource WukongCRM 9.0 and classified as problematic. This issue affects some unkno

4.3
CVE-2025-49857

Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control

4.3
CVE-2025-49874

Missing Authorization vulnerability in tychesoftwares Arconix FAQ arconix-faq allows Exploiting Incorrectly Configured A

4.3
CVE-2025-49880

Missing Authorization vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Exploiting Incorrectly Configured

4.3
CVE-2025-23999

Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control S

4.3
CVE-2025-6284

A vulnerability was found in PHPGurukul Car Rental Portal 3.0. It has been declared as problematic. This vulnerability a

4.3
CVE-2025-6341

A vulnerability classified as problematic was found in code-projects School Fees Payment System 1.0. This vulnerability

4.3
CVE-2025-49969

Missing Authorization vulnerability in Zara 4 Zara 4 Image Compression zara-4 allows Exploiting Incorrectly Configured A

4.3
CVE-2025-49970

Missing Authorization vulnerability in sparklewpthemes Hello FSE Blog hello-fse-blog allows Exploiting Incorrectly Confi

4.3
CVE-2025-49971

Missing Authorization vulnerability in aThemeArt Translations eDS Responsive Menu eds-responsive-menu allows Exploiting

4.3
CVE-2025-49973

Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Siz

4.3
CVE-2025-49974

Missing Authorization vulnerability in upstreamplugin UpStream: a Project Management Plugin for WordPress upstream allow

4.3
CVE-2025-49976

Missing Authorization vulnerability in WANotifier Notifier notifier allows Exploiting Incorrectly Configured Access Cont

4.3
CVE-2025-49979

Missing Authorization vulnerability in slui Media Hygiene media-hygiene allows Exploiting Incorrectly Configured Access

4.3
CVE-2025-49980

Missing Authorization vulnerability in WP Event Manager WP User Profile Avatar wp-user-profile-avatar allows Exploiting

4.3
CVE-2025-49981

Missing Authorization vulnerability in mahabub81 User Roles and Capabilities user-roles-and-capabilities allows Exploiti

4.3
CVE-2025-49982

Missing Authorization vulnerability in aguilatechnologies WP Customer Area customer-area allows Exploiting Incorrectly C

4.3
CVE-2025-6476

A vulnerability was found in SourceCodester Gym Management System 1.0. It has been classified as problematic. Affected i

4.3
CVE-2025-6478

A vulnerability was found in CodeAstro Expense Management System 1.0. It has been rated as problematic. Affected by this

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started