Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 98/188
4.3
CVE-2025-52878

In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions

4.3
CVE-2025-6664

A vulnerability, which was classified as problematic, was found in CodeAstro Patient Record Management System 1.0. Affec

4.3
CVE-2025-3863

The Post Carousel Slider for Elementor plugin for WordPress is vulnerable to improper authorization due to a missing cap

4.3
CVE-2025-5812

The VG WORT METIS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch

4.3
CVE-2025-5315

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18

4.3
CVE-2025-53200

Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Cont

4.3
CVE-2025-53266

Missing Authorization vulnerability in EdwardBock Cron Logger cron-logger allows Exploiting Incorrectly Configured Acces

4.3
CVE-2025-53288

Missing Authorization vulnerability in Adrian Ladó PlatiOnline Payments plationline allows Exploiting Incorrectly Config

4.3
CVE-2025-53293

Missing Authorization vulnerability in Morten Dalgaard Johansen Dashboard Widget Sidebar dashboard-widget-sidebar allows

4.3
CVE-2025-53323

Missing Authorization vulnerability in danbriapps Pre-Publish Post Checklist pre-publish-post-checklist allows Exploitin

4.3
CVE-2025-6864

A vulnerability, which was classified as problematic, has been found in SeaCMS up to 13.2. Affected by this issue is som

4.3
CVE-2025-6865

A vulnerability, which was classified as problematic, was found in DaiCuo up to 1.3.13. This affects an unknown part of

4.3
CVE-2025-52554

n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /re

4.3
CVE-2025-29001

Missing Authorization vulnerability in ZoomIt WooCommerce Shop Page Builder allows Exploiting Incorrectly Configured Acc

4.3
CVE-2025-29007

Missing Authorization vulnerability in LMSACE LMSACE Connect lmsace-connect allows Exploiting Incorrectly Configured Acc

4.3
CVE-2025-7078

A vulnerability classified as problematic was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.3.9. This vulnerability

4.3
CVE-2025-7133

A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affec

4.3
CVE-2025-53374

Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an

4.3
CVE-2025-42960

SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than inte

4.3
CVE-2025-42974

Due to missing authorization check, an attacker authenticated as a non-administrative user could call a remote-enabled f

4.3
CVE-2025-42986

Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privi

4.3
CVE-2025-48150

Missing Authorization vulnerability in sminozzi Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugi

4.3
CVE-2025-53997

Missing Authorization vulnerability in favethemes Houzez houzez allows Exploiting Incorrectly Configured Access Control

4.3
CVE-2025-54011

Missing Authorization vulnerability in SMTP2GO SMTP2GO smtp2go allows Exploiting Incorrectly Configured Access Control S

4.3
CVE-2025-54018

Missing Authorization vulnerability in CreativeMindsSolutions CM Pop-Up banners cm-pop-up-banners allows Exploiting Inco

4.3
CVE-2025-54047

Missing Authorization vulnerability in QuanticaLabs Cost Calculator ql-cost-calculator allows Exploiting Incorrectly Con

4.3
CVE-2025-7756

A vulnerability classified as problematic has been found in code-projects E-Commerce Site 1.0. Affected is an unknown fu

4.3
CVE-2025-5816

The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecure

4.3
CVE-2025-6726

The Block Editor Gallery Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing

4.3
CVE-2025-7834

A vulnerability, which was classified as problematic, was found in PHPGurukul Complaint Management System 2.0. Affected

4.3
CVE-2025-1299

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions start

4.3
CVE-2025-7822

The WP Wallcreeper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c

4.3
CVE-2025-8223

A vulnerability, which was classified as problematic, was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f

4.3
CVE-2025-6730

The Bonanza – WooCommerce Free Gifts Lite plugin for WordPress is vulnerable to unauthorized modification of data due to

4.3
CVE-2025-53112

GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and

4.3
CVE-2025-8335

A vulnerability classified as problematic has been found in code-projects Simple Car Rental System 1.0. This affects an

4.3
CVE-2025-8488

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to una

4.3
CVE-2025-8505

A vulnerability has been found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as pro

4.3
CVE-2025-8595

The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the w

4.3
CVE-2025-8739

A vulnerability was found in zhenfeng13 My-Blog up to 1.0.0 and classified as problematic. This issue affects some unkno

4.3
CVE-2025-8814

A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function setC

4.3
CVE-2025-8482

The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This

4.3
CVE-2025-49052

Missing Authorization vulnerability in Dariolee Netease Music netease-music allows Exploiting Incorrectly Configured Acc

4.3
CVE-2025-54705

Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured

4.3
CVE-2025-20302

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-pri

4.3
CVE-2025-53221

Missing Authorization vulnerability in codeablepress CodeablePress codeablepress-simple-frontend-profile-picture-upload

4.3
CVE-2025-53341

Missing Authorization vulnerability in Themovation App, SaaS & Software Startup Tech Theme - Stratus stratusx allows Exp

4.3
CVE-2025-53343

Missing Authorization vulnerability in GoodLayers Modernize modernize allows Exploiting Incorrectly Configured Access Co

4.3
CVE-2025-54712

Missing Authorization vulnerability in hashthemes Easy Elementor Addons easy-elementor-addons allows Exploiting Incorrec

4.3
CVE-2025-55716

Missing Authorization vulnerability in VeronaLabs WP Statistics wp-statistics allows Exploiting Incorrectly Configured A

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started