In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions
A vulnerability, which was classified as problematic, was found in CodeAstro Patient Record Management System 1.0. Affec
The Post Carousel Slider for Elementor plugin for WordPress is vulnerable to improper authorization due to a missing cap
The VG WORT METIS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch
An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18
Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Cont
Missing Authorization vulnerability in EdwardBock Cron Logger cron-logger allows Exploiting Incorrectly Configured Acces
Missing Authorization vulnerability in Adrian Ladó PlatiOnline Payments plationline allows Exploiting Incorrectly Config
Missing Authorization vulnerability in Morten Dalgaard Johansen Dashboard Widget Sidebar dashboard-widget-sidebar allows
Missing Authorization vulnerability in danbriapps Pre-Publish Post Checklist pre-publish-post-checklist allows Exploitin
A vulnerability, which was classified as problematic, has been found in SeaCMS up to 13.2. Affected by this issue is som
A vulnerability, which was classified as problematic, was found in DaiCuo up to 1.3.13. This affects an unknown part of
n8n is a workflow automation platform. Prior to version 1.99.1, an authorization vulnerability was discovered in the /re
Missing Authorization vulnerability in ZoomIt WooCommerce Shop Page Builder allows Exploiting Incorrectly Configured Acc
Missing Authorization vulnerability in LMSACE LMSACE Connect lmsace-connect allows Exploiting Incorrectly Configured Acc
A vulnerability classified as problematic was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.3.9. This vulnerability
A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affec
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an
SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than inte
Due to missing authorization check, an attacker authenticated as a non-administrative user could call a remote-enabled f
Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privi
Missing Authorization vulnerability in sminozzi Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugi
Missing Authorization vulnerability in favethemes Houzez houzez allows Exploiting Incorrectly Configured Access Control
Missing Authorization vulnerability in SMTP2GO SMTP2GO smtp2go allows Exploiting Incorrectly Configured Access Control S
Missing Authorization vulnerability in CreativeMindsSolutions CM Pop-Up banners cm-pop-up-banners allows Exploiting Inco
Missing Authorization vulnerability in QuanticaLabs Cost Calculator ql-cost-calculator allows Exploiting Incorrectly Con
A vulnerability classified as problematic has been found in code-projects E-Commerce Site 1.0. Affected is an unknown fu
The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecure
The Block Editor Gallery Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
A vulnerability, which was classified as problematic, was found in PHPGurukul Complaint Management System 2.0. Affected
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions start
The WP Wallcreeper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c
A vulnerability, which was classified as problematic, was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 up to 24a15c02b4f
The Bonanza – WooCommerce Free Gifts Lite plugin for WordPress is vulnerable to unauthorized modification of data due to
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and
A vulnerability classified as problematic has been found in code-projects Simple Car Rental System 1.0. This affects an
The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to una
A vulnerability has been found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as pro
The Zakra theme for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the w
A vulnerability was found in zhenfeng13 My-Blog up to 1.0.0 and classified as problematic. This issue affects some unkno
A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function setC
The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This
Missing Authorization vulnerability in Dariolee Netease Music netease-music allows Exploiting Incorrectly Configured Acc
Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured
A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, low-pri
Missing Authorization vulnerability in codeablepress CodeablePress codeablepress-simple-frontend-profile-picture-upload
Missing Authorization vulnerability in Themovation App, SaaS & Software Startup Tech Theme - Stratus stratusx allows Exp
Missing Authorization vulnerability in GoodLayers Modernize modernize allows Exploiting Incorrectly Configured Access Co
Missing Authorization vulnerability in hashthemes Easy Elementor Addons easy-elementor-addons allows Exploiting Incorrec
Missing Authorization vulnerability in VeronaLabs WP Statistics wp-statistics allows Exploiting Incorrectly Configured A
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started