CWE-266: CWE-266

414
Total CVEs
48
Critical
128
High
6.7
Avg CVSS

Yearly Trend

2026
74
2025
267
2024
59
2023
5
2022
4

Top Affected Vendors

1 Jeecg 11
2 Portabilis 11
3 Dell 10
4 Google 9
5 Fuyang Lipengjun 8
6 Macrozheng 8
7 Dlink 8
8 Totolink 7
9 Wekan Project 7
10 Youlai 6

All CWE-266 CVEs (414)

CVE-2025-69182
8.8

This vulnerability allows attackers to escalate privileges in the WordPress Institutions Directory plugin. Attackers could gain administrative access ...

Jan 22, 2026
CVE-2025-69183
8.8

This vulnerability allows attackers to escalate privileges in the Hospital Doctor Directory WordPress plugin, potentially gaining administrative acces...

Jan 22, 2026
CVE-2025-67966
8.8

This vulnerability allows attackers to escalate privileges in the Lawyer Directory WordPress plugin due to incorrect privilege assignment. Attackers c...

Jan 22, 2026
CVE-2025-50007
8.8

This vulnerability allows attackers to escalate privileges in the Jthemes xSmart WordPress theme due to incorrect privilege assignment. Attackers can ...

Jan 22, 2026
CVE-2025-31643
8.8

This vulnerability allows attackers to escalate privileges in Dasinfomedia WPCHURCH WordPress plugin, potentially gaining administrative access. It af...

Jan 7, 2026
CVE-2025-29004
8.8

This CVE describes an Incorrect Privilege Assignment vulnerability in two AA-Team WordPress plugins that allows attackers to escalate privileges. It a...

Jan 6, 2026
CVE-2025-59134
8.8

This CVE describes an incorrect privilege assignment vulnerability in the Jthemes Sale! Immigration law WordPress theme (immiex) that allows authentic...

Dec 18, 2025
CVE-2025-66296
8.8

A privilege escalation vulnerability in Grav's Admin plugin allows users with create-user permissions to overwrite administrator accounts by creating ...

Dec 1, 2025
CVE-2025-45311
8.8

This CVE describes a privilege escalation vulnerability in fail2ban-client v0.11.2 where users with limited sudo privileges can execute arbitrary comm...

Nov 26, 2025
CVE-2025-65094
8.8

This vulnerability allows low-privileged users in WBCE CMS to escalate their privileges to full administrative access by manipulating the groups[] par...

Nov 19, 2025
CVE-2025-2843
8.8

This vulnerability allows Kubernetes users with only namespace-level permissions to create a MonitorStack resource, which triggers the Observability O...

Nov 12, 2025
CVE-2025-62034
8.8

This CVE describes an incorrect privilege assignment vulnerability in the uxper Togo WordPress theme that allows privilege escalation. Attackers can g...

Nov 6, 2025
CVE-2025-49900
8.8

This vulnerability allows attackers to escalate privileges in the Advanced Scrollbar WordPress plugin. It affects WordPress sites using Advanced Scrol...

Nov 6, 2025
CVE-2025-62007
8.8

This vulnerability allows attackers to escalate privileges in the Voice Feedback WordPress plugin due to incorrect privilege assignment. Attackers can...

Oct 22, 2025
CVE-2025-60211
8.8

This vulnerability allows attackers to escalate privileges in WordPress sites using the extendons WooCommerce Registration Fields Plugin. Attackers ca...

Oct 22, 2025
CVE-2025-59580
8.8

This vulnerability allows attackers to escalate privileges in WordPress sites using the Goodlayers Core plugin. Attackers could gain administrative ac...

Oct 22, 2025
CVE-2025-48165
8.8

CVE-2025-48165 is an incorrect privilege assignment vulnerability in the DELUCKS SEO WordPress plugin that allows authenticated attackers to escalate ...

Aug 20, 2025
CVE-2025-48142
8.8

CVE-2025-48142 is an incorrect privilege assignment vulnerability in the Bookify WordPress plugin that allows authenticated users to escalate their pr...

Aug 20, 2025
CVE-2025-39542
8.8

CVE-2025-39542 is an incorrect privilege assignment vulnerability in Jauhari Xelion Xelion Webchat WordPress plugin that allows authenticated attacker...

Apr 17, 2025
CVE-2025-1653
8.8

The uListing WordPress plugin has a privilege escalation vulnerability that allows authenticated users with Subscriber-level access or higher to eleva...

Mar 15, 2025
CVE-2024-40591
8.8

This vulnerability allows authenticated administrators with Security Fabric permission to escalate their privileges to super-admin by connecting their...

Feb 11, 2025
CVE-2025-23528
8.8

This vulnerability in the Wouter Dijkstra DD Roles WordPress plugin allows attackers to escalate privileges due to incorrect privilege assignment. It ...

Jan 16, 2025
CVE-2024-13251
8.8

This vulnerability allows attackers to gain elevated privileges through incorrect privilege assignment in Drupal's Registration role module. It affect...

Jan 9, 2025
CVE-2024-56280
8.8

This vulnerability allows attackers to escalate privileges in WPGuppy WordPress plugins, potentially gaining administrative access. It affects all WPG...

Jan 7, 2025
CVE-2024-49644
8.8

This vulnerability allows attackers to escalate privileges in the AllAccessible WordPress plugin, potentially gaining administrative access to WordPre...

Jan 7, 2025
CVE-2024-50506
8.8

This vulnerability allows attackers to escalate privileges in Azexo Marketing Automation WordPress plugins. Attackers could gain administrative access...

Oct 30, 2024
CVE-2024-50481
8.8

This vulnerability allows attackers to escalate privileges in WordPress sites using the Bstone Demo Importer plugin. Attackers can gain administrative...

Oct 29, 2024
CVE-2024-49608
8.8

This vulnerability allows attackers to escalate privileges in the GERRYWORKS Post by Mail WordPress plugin. Users with lower-level permissions can gai...

Oct 20, 2024
CVE-2024-22303
8.8

This vulnerability allows attackers to escalate privileges in the Houzez WordPress theme due to incorrect privilege assignment. Attackers can gain adm...

Sep 17, 2024
CVE-2024-8253
8.8

The Post Grid and Gutenberg Blocks WordPress plugin has a privilege escalation vulnerability that allows authenticated users with subscriber-level acc...

Sep 11, 2024
CVE-2024-40433
8.8

This vulnerability in Tencent WeChat's web-view component allows attackers to bypass permission controls and access sensitive data like cookies. It af...

Jul 26, 2024
CVE-2023-49647
8.8

This vulnerability allows authenticated users on Windows systems to escalate their privileges through local access to the Zoom Desktop Client, Zoom VD...

Jan 12, 2024
CVE-2022-20759
8.8

This vulnerability allows authenticated but unprivileged remote attackers to escalate privileges to level 15 (highest administrative level) on Cisco A...

May 3, 2022
CVE-2023-2816
8.7

This vulnerability allows users with service:write permissions in Consul to modify Envoy proxy configurations for downstream services they don't own. ...

Jun 2, 2023
CVE-2025-58710
8.6

This vulnerability allows attackers to escalate privileges in the Hotel Listing WordPress plugin, potentially gaining administrative access. It affect...

Dec 18, 2025
CVE-2025-52726
8.6

This vulnerability in the CouponXxL Custom Post Types WordPress plugin allows attackers to escalate privileges due to incorrect privilege assignment. ...

Jun 27, 2025
CVE-2024-25632
8.6

This vulnerability in eLabFTW allows regular users to escalate privileges to administrator within teams where they are members. In versions after v5.0...

Oct 1, 2024
CVE-2024-27453
8.6

This vulnerability allows a read-only user on Extreme XOS network switches to escalate privileges to root administrator access by sending a specially ...

May 3, 2024
CVE-2023-50437
8.6

CVE-2023-50437 exposes sensitive authentication cookies (otpCookie) to administrators through specific API endpoints in Couchbase Server. This allows ...

Feb 29, 2024
CVE-2025-65807
8.4

This vulnerability in sd command v1.0.0 and earlier allows attackers to escalate privileges to root via specially crafted commands. It affects systems...

Dec 10, 2025
CVE-2023-30691
8.4

This vulnerability allows a local attacker to escalate privileges on Samsung devices due to a parcel mismatch in AuthenticationConfig. It affects Sams...

Aug 10, 2023
CVE-2025-48911
8.2

This vulnerability involves improper permission assignment in a note sharing module, allowing unauthorized access or manipulation of shared notes. Suc...

Jun 6, 2025
CVE-2026-22267
8.1

Dell PowerProtect Data Manager versions before 19.22 have an incorrect privilege assignment vulnerability that allows low-privileged remote attackers ...

Feb 19, 2026
CVE-2025-67953
8.1

This vulnerability allows attackers to escalate privileges in the Booking Activities WordPress plugin. Any WordPress site running Booking Activities v...

Jan 22, 2026
CVE-2025-4922
8.1

This vulnerability in Nomad's ACL policy lookup system can cause incorrect rule application and shadowing, potentially allowing unauthorized access to...

Jun 11, 2025
CVE-2025-23974
8.1

CVE-2025-23974 is an incorrect privilege assignment vulnerability in the ifkooo One-Login WordPress plugin that allows authenticated attackers to esca...

Jun 9, 2025
CVE-2025-0628
8.1

An improper authorization vulnerability in BerriAI/litellm grants internal_user_viewer accounts an overly privileged API key, allowing them to access ...

Mar 20, 2025
CVE-2024-50550
8.1

This vulnerability allows attackers to escalate privileges in LiteSpeed Cache WordPress plugin due to incorrect privilege assignment. Attackers can ga...

Oct 29, 2024
CVE-2025-33179
8.0

This vulnerability in NVIDIA Cumulus Linux and NVOS allows low-privileged users to execute unauthorized commands through the NVUE interface, potential...

Feb 24, 2026
CVE-2025-13130
7.8

A local privilege escalation vulnerability in Radarr 5.28.0.10274 allows attackers with local access to manipulate service permissions. This could ena...

Nov 13, 2025

About CWE-266 (CWE-266)

Our database tracks 414 CVEs classified as CWE-266, with 48 rated critical and 128 rated high severity. The average CVSS score for CWE-266 vulnerabilities is 6.7.

External reference: View CWE-266 on MITRE CWE →

Monitor CWE-266 Vulnerabilities

Get alerted when new CWE-266 CVEs affect your infrastructure.

Start Monitoring Free