CWE-266: CWE-266

414
Total CVEs
48
Critical
128
High
6.7
Avg CVSS

Yearly Trend

2026
74
2025
267
2024
59
2023
5
2022
4

Top Affected Vendors

1 Jeecg 11
2 Portabilis 11
3 Dell 10
4 Google 9
5 Fuyang Lipengjun 8
6 Macrozheng 8
7 Dlink 8
8 Totolink 7
9 Wekan Project 7
10 Youlai 6

All CWE-266 CVEs (414)

CVE-2026-23800
10.0

This vulnerability allows attackers to escalate privileges in Modular DS modular-connector WordPress plugin. Attackers can gain higher-level permissio...

Jan 16, 2026
CVE-2026-23550
10.0

This critical vulnerability in Modular DS allows attackers to escalate privileges due to incorrect privilege assignment. It affects all versions up to...

Jan 14, 2026
CVE-2025-41115
10.0

A critical vulnerability in Grafana's SCIM provisioning allows malicious SCIM clients to provision users with numeric external IDs, potentially overri...

Nov 21, 2025
CVE-2026-22907
9.9

This critical vulnerability allows attackers to bypass security controls and access the host filesystem, enabling unauthorized reading and modificatio...

Jan 15, 2026
CVE-2025-62645
9.9

This vulnerability allows remote authenticated attackers to obtain administrative tokens via a GraphQL mutation in the Restaurant Brands International...

Oct 17, 2025
CVE-2025-10725
9.9

A privilege escalation vulnerability in Red Hat OpenShift AI Service allows authenticated low-privileged users (like data scientists using Jupyter not...

Sep 30, 2025
CVE-2025-26512
9.9

This vulnerability allows authenticated SnapCenter Server users to escalate privileges to admin level on remote systems where SnapCenter plug-ins are ...

Mar 24, 2025
CVE-2025-68869
9.8

This vulnerability allows attackers to escalate privileges in LazyTasks project management software, potentially gaining administrative access. It aff...

Jan 22, 2026
CVE-2025-64188
9.8

CVE-2025-64188 is an incorrect privilege assignment vulnerability in the Soledad WordPress theme that allows attackers to escalate privileges. This af...

Dec 18, 2025
CVE-2025-6325
9.8

This vulnerability allows attackers to escalate privileges in WordPress sites using the King Addons for Elementor plugin. Attackers can gain administr...

Nov 6, 2025
CVE-2025-60243
9.8

This vulnerability allows attackers to gain higher privileges than intended in the Selling Commander for WooCommerce plugin. Attackers can escalate fr...

Nov 6, 2025
CVE-2025-60195
9.8

This vulnerability allows attackers to escalate privileges in the Atarim Visual Collaboration WordPress plugin, potentially gaining administrative acc...

Nov 6, 2025
CVE-2025-60220
9.8

This vulnerability allows attackers to escalate privileges in the CouponXxL WordPress theme due to incorrect privilege assignment. Attackers can gain ...

Oct 22, 2025
CVE-2024-32444
9.8

CVE-2024-32444 is an incorrect privilege assignment vulnerability in the RealHomes WordPress theme that allows attackers to escalate privileges, poten...

Sep 3, 2025
CVE-2025-44655
9.8

This vulnerability in TOTOLink routers allows attackers to bypass FTP directory restrictions due to misconfigured vsftpd settings. Attackers can acces...

Jul 21, 2025
CVE-2025-52836
9.8

This vulnerability allows attackers to escalate privileges in The E-Commerce ERP WordPress plugin, potentially gaining administrative access. It affec...

Jul 16, 2025
CVE-2025-49867
9.8

CVE-2025-49867 is an incorrect privilege assignment vulnerability in the RealHomes WordPress theme that allows attackers to escalate privileges to adm...

Jul 4, 2025
CVE-2025-23970
9.8

This vulnerability allows attackers to escalate privileges in the Service Finder Booking WordPress plugin, potentially gaining administrative access. ...

Jul 4, 2025
CVE-2025-48129
9.8

This vulnerability allows attackers to escalate privileges in WordPress sites using the Spreadsheet Price Changer plugin. Attackers can gain administr...

Jun 9, 2025
CVE-2025-47539
EPSS 25.3% 9.8

This vulnerability allows attackers to escalate privileges in the Themewinter Eventin WordPress plugin, potentially gaining administrative access. It ...

May 23, 2025
CVE-2025-39489
9.8

CVE-2025-39489 is an incorrect privilege assignment vulnerability in the CouponXL WordPress theme that allows attackers to escalate privileges to admi...

May 23, 2025
CVE-2025-31918
9.8

This vulnerability allows attackers to escalate privileges in the Simple Business Directory Pro WordPress plugin, potentially gaining administrative a...

May 23, 2025
CVE-2025-27007
EPSS 73.9% 9.8

This vulnerability allows attackers to escalate privileges in Brainstorm Force SureTriggers WordPress plugin, potentially gaining administrative acces...

May 1, 2025
CVE-2025-32980
9.8

NETSCOUT nGeniusONE before version 6.4.0 P11 b3245 has a weak sudo configuration that allows local users to escalate privileges. This affects organiza...

Apr 25, 2025
CVE-2025-2470
9.8

This vulnerability allows unauthenticated attackers to register WordPress accounts with arbitrary roles, including Administrator, when using social lo...

Apr 25, 2025
CVE-2025-32648
9.8

This vulnerability allows attackers to escalate privileges in Projectopia Projectopia, a WordPress project management plugin. Attackers can gain admin...

Apr 17, 2025
CVE-2025-32491
9.8

This vulnerability allows attackers to escalate privileges in Rankology SEO WordPress plugin, potentially gaining administrative access. It affects al...

Apr 11, 2025
CVE-2025-32695
9.8

This vulnerability allows attackers to escalate privileges in the Checkout Mestres WP WordPress plugin. Attackers can gain administrative access to Wo...

Apr 9, 2025
CVE-2024-51800
9.8

CVE-2024-51800 is an incorrect privilege assignment vulnerability in the Favethemes Homey WordPress theme that allows attackers to escalate privileges...

Apr 4, 2025
CVE-2025-2345
9.8

This critical vulnerability in IROAD dash cams allows remote attackers to bypass authorization controls, potentially accessing sensitive data or manip...

Mar 16, 2025
CVE-2024-8420
9.8

The DHVC Form WordPress plugin has a privilege escalation vulnerability that allows unauthenticated attackers to register as administrators. This affe...

Feb 28, 2025
CVE-2024-56000
9.8

CVE-2024-56000 is an incorrect privilege assignment vulnerability in SeventhQueen's K Elements WordPress plugin that allows unauthenticated attackers ...

Feb 18, 2025
CVE-2024-12213
9.8

The WP Job Board Pro WordPress plugin has a critical privilege escalation vulnerability that allows unauthenticated attackers to register as administr...

Feb 12, 2025
CVE-2024-13421
9.8

This vulnerability in the Real Estate 7 WordPress theme allows unauthenticated attackers to register new administrative user accounts due to improper ...

Feb 12, 2025
CVE-2024-32555
9.8

This vulnerability allows attackers to escalate privileges in the Easy Real Estate WordPress plugin due to incorrect privilege assignment. Attackers c...

Jan 21, 2025
CVE-2024-12470
9.8

The SakolaWP WordPress plugin allows unauthenticated attackers to register as administrative users due to improper role validation. This affects all W...

Jan 7, 2025
CVE-2024-56040
9.8

This vulnerability allows unauthenticated attackers to escalate privileges in VibeThemes VibeBP WordPress plugin, potentially gaining administrative a...

Dec 31, 2024
CVE-2024-56071
9.8

This vulnerability allows attackers to escalate privileges in Simple Dashboard WordPress plugin, potentially gaining administrative access. It affects...

Dec 31, 2024
CVE-2024-56220
9.8

This vulnerability allows attackers to escalate privileges in SSL Wireless SMS Notification WordPress plugin, enabling unauthorized users to gain admi...

Dec 31, 2024
CVE-2024-54383
9.8

This vulnerability allows attackers to gain elevated privileges in WooCommerce PDF Vouchers WordPress plugin due to incorrect privilege assignment. At...

Dec 18, 2024
CVE-2024-50485
9.8

This vulnerability allows attackers to escalate privileges in the Exam Matrix WordPress plugin due to incorrect privilege assignment. Attackers can ga...

Oct 29, 2024
CVE-2024-49217
9.8

This vulnerability in the WordPress 'Adding drop down roles in registration' plugin allows attackers to assign themselves administrative or other priv...

Oct 17, 2024
CVE-2024-28000
9.8

This vulnerability allows unauthenticated attackers to escalate privileges in the LiteSpeed Cache WordPress plugin. Attackers can gain administrative ...

Aug 21, 2024
CVE-2026-22908
9.1

This vulnerability allows remote attackers to gain full system access by uploading unvalidated container images to affected systems. It compromises bo...

Jan 15, 2026
CVE-2025-13888
9.1

This vulnerability allows authenticated namespace administrators in OpenShift GitOps to create ArgoCD Custom Resources that grant them elevated permis...

Dec 15, 2025
CVE-2025-45006
9.1

This vulnerability in Rocket Chip RISC-V processors allows unauthorized access to physical memory due to improper retention of the mstatus.SUM bit. It...

Jul 1, 2025
CVE-2025-23391
9.1

A privilege escalation vulnerability in SUSE Rancher allows Restricted Administrators to change passwords of full Administrators, enabling account tak...

Apr 11, 2025
CVE-2024-25660
9.0

CVE-2024-25660 allows low-privileged remote attackers to perform unauthorized file operations through the WebDAV service in Infinera TNMS due to exces...

Oct 1, 2024
CVE-2025-69292
8.8

This vulnerability allows attackers to escalate privileges in the WP Membership WordPress plugin, potentially granting unauthorized administrative acc...

Jan 22, 2026
CVE-2025-69293
8.8

This vulnerability in the WordPress Final User plugin allows attackers to escalate privileges due to incorrect privilege assignment. Users running ver...

Jan 22, 2026

About CWE-266 (CWE-266)

Our database tracks 414 CVEs classified as CWE-266, with 48 rated critical and 128 rated high severity. The average CVSS score for CWE-266 vulnerabilities is 6.7.

External reference: View CWE-266 on MITRE CWE →

Monitor CWE-266 Vulnerabilities

Get alerted when new CWE-266 CVEs affect your infrastructure.

Start Monitoring Free