CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,010
Total CVEs
217
Critical
827
High
6.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
436
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 110
2 Sap 32
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Q Free 11
9 Wpdeveloper 11
10 Apache 10

All Missing Authorization CVEs (3,010)

CVE-2026-0490
7.5

CVE-2026-0490 is an authentication bypass vulnerability in SAP BusinessObjects BI Platform that allows unauthenticated attackers to send crafted netwo...

Feb 10, 2026
CVE-2026-25808
7.5

This vulnerability in Hollo microblogging software exposes private direct messages and followers-only posts through the ActivityPub outbox endpoint wi...

Feb 9, 2026
CVE-2025-15285
7.5

The SEO Flow by LupsOnline WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to create, modify, and del...

Feb 4, 2026
CVE-2026-1280
7.5

This vulnerability in the Frontend File Manager WordPress plugin allows unauthenticated attackers to share any uploaded file via email by exploiting a...

Jan 28, 2026
CVE-2025-69313
7.5

This CVE describes a missing authorization vulnerability in the WPXPO PostX ultimate-post WordPress plugin that allows attackers to bypass access cont...

Jan 22, 2026
CVE-2025-68882
7.5

This CVE describes a missing authorization vulnerability in the Scalenut WordPress plugin that allows attackers to bypass access controls. It affects ...

Jan 22, 2026
CVE-2025-14070
7.5

The Reviewify WordPress plugin has an authorization vulnerability that allows authenticated users with Contributor-level access or higher to create ar...

Jan 7, 2026
CVE-2025-13493
7.5

This vulnerability in the Latest Registered Users WordPress plugin allows unauthenticated attackers to export complete user data (excluding passwords)...

Jan 7, 2026
CVE-2025-11877
7.5

The User Activity Log WordPress plugin up to version 2.2 contains an unauthenticated vulnerability that allows attackers to modify critical WordPress ...

Jan 7, 2026
CVE-2025-68036
7.5

This CVE describes a missing authorization vulnerability in CubeWP WordPress plugin that allows attackers to access functionality not properly restric...

Dec 30, 2025
CVE-2025-68568
7.5

This CVE describes a Missing Authorization vulnerability in the claspo Popup Builder WordPress plugin that allows attackers to bypass access controls....

Dec 24, 2025
CVE-2024-24844
7.5

CVE-2024-24844 is a missing authorization vulnerability in PowerPack Pro for Elementor WordPress plugin that allows unauthenticated attackers to reset...

Dec 23, 2025
CVE-2025-12980
7.5

This vulnerability allows unauthenticated attackers to access sensitive user metadata including password hashes via a REST API endpoint in the PostX W...

Dec 21, 2025
CVE-2025-66117
7.5

This CVE describes a Missing Authorization vulnerability in the Ays Pro Easy Form WordPress plugin that allows attackers to bypass access controls. It...

Dec 18, 2025
CVE-2025-66054
7.5

This CVE describes a missing authorization vulnerability in the LearnPress WordPress plugin that allows attackers to bypass access controls and perfor...

Dec 18, 2025
CVE-2025-66070
7.5

This CVE describes a missing authorization vulnerability in the wpForo Forum WordPress plugin that allows attackers to bypass access controls. It affe...

Dec 18, 2025
CVE-2025-66088
7.5

This CVE describes a missing authorization vulnerability in PropertyHive WordPress plugin that allows attackers to bypass access controls. It affects ...

Dec 18, 2025
CVE-2025-64378
7.5

This CVE describes a Missing Authorization vulnerability in the ListingPro WordPress theme that allows attackers to bypass access controls. It affects...

Dec 18, 2025
CVE-2025-64268
7.5

This CVE describes a Missing Authorization vulnerability in the Arraytics Timetics WordPress plugin that allows attackers to bypass access controls. I...

Dec 18, 2025
CVE-2025-64273
7.5

This CVE describes a Missing Authorization vulnerability in the GetResponse Email Marketing WordPress plugin that allows attackers to exploit incorrec...

Dec 18, 2025
CVE-2025-64222
7.5

This CVE describes a Missing Authorization vulnerability in the FantasticPlugins WooCommerce Recover Abandoned Cart plugin that allows attackers to de...

Dec 18, 2025
CVE-2025-64209
7.5

This CVE describes a missing authorization vulnerability in the Masterstudy WordPress theme that allows attackers to access functionality not properly...

Dec 18, 2025
CVE-2025-64214
7.5

This CVE describes a missing authorization vulnerability in the MasterStudy LMS Pro WordPress plugin that allows attackers to access functionality not...

Dec 18, 2025
CVE-2025-60086
7.5

This CVE describes a Missing Authorization vulnerability in the WP Voting Contest WordPress plugin that allows attackers to exploit incorrectly config...

Dec 18, 2025
CVE-2025-60077
7.5

This CVE describes a missing authorization vulnerability in the YayPricing WordPress plugin that allows attackers to access functionality not properly...

Dec 18, 2025
CVE-2025-60045
7.5

This CVE describes a Missing Authorization vulnerability in the ThemeAtelier IDonatePro WordPress plugin that allows attackers to access functionality...

Dec 18, 2025
CVE-2025-58877
7.5

This CVE describes a Missing Authorization vulnerability in the Javo Core WordPress plugin that allows attackers to delete arbitrary content without p...

Dec 18, 2025
CVE-2025-54159
7.5

This CVE describes a missing authorization vulnerability in Synology BeeDrive desktop software that allows remote attackers to delete arbitrary files ...

Dec 4, 2025
CVE-2025-46175
7.5

Ruoyi v4.8.0 has an incorrect access control vulnerability where the authRole method in SysUserController.java lacks a checkUserDataScope permission c...

Nov 26, 2025
CVE-2025-46174
7.5

Ruoyi v4.8.0 has an incorrect access control vulnerability in the resetPwd method that allows unauthorized password resets. Attackers can reset passwo...

Nov 26, 2025
CVE-2025-13384
7.5

This vulnerability allows unauthenticated attackers to forge PayPal payment notifications in the CP Contact Form with PayPal WordPress plugin, marking...

Nov 22, 2025
CVE-2025-12955
7.5

The Live Sales Notification for WooCommerce WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to access...

Nov 18, 2025
CVE-2025-64404
7.5

Apache OpenOffice versions through 4.1.15 have a missing authorization vulnerability that allows attackers to craft documents that automatically load ...

Nov 12, 2025
CVE-2025-64405
7.5

Apache OpenOffice versions through 4.1.15 have a missing authorization vulnerability where specially crafted Calc spreadsheets containing DDE links ca...

Nov 12, 2025
CVE-2025-64401
7.5

Apache OpenOffice versions through 4.1.15 contain a missing authorization vulnerability where documents with floating frames linked to external files ...

Nov 12, 2025
CVE-2025-12633
7.5

The Bookit WordPress plugin has a missing capability check on its Stripe return endpoint, allowing unauthenticated attackers to connect their own Stri...

Nov 12, 2025
CVE-2025-58629
7.5

This CVE describes a Missing Authorization vulnerability in the Miraculous WordPress theme that allows attackers to delete arbitrary content without p...

Nov 6, 2025
CVE-2025-41335
7.5

An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential information by manipulating POST param...

Nov 4, 2025
CVE-2025-41336
7.5

An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' information by manipulating the 'web' parameter in ...

Nov 4, 2025
CVE-2025-41337
7.5

An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' information by manipulating the 'web' parameter in ...

Nov 4, 2025
CVE-2025-41338
7.5

An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' information by manipulating POST parameters. Attack...

Nov 4, 2025
CVE-2025-41339
7.5

An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential information by manipulating the 'id_so...

Nov 4, 2025
CVE-2025-41113
7.5

An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential reports by manipulating the 'id_denunc...

Nov 4, 2025
CVE-2025-41114
7.5

An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential documents by manipulating POST paramet...

Nov 4, 2025
CVE-2025-41111
7.5

An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential information by manipulating the 'id_de...

Nov 4, 2025
CVE-2025-41112
7.5

An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential information by manipulating the 'web' ...

Nov 4, 2025
CVE-2025-11890
7.5

This vulnerability allows unauthenticated attackers to bypass payment verification in WooCommerce stores using the Crypto Payment Gateway with Payeer ...

Nov 4, 2025
CVE-2025-62022
7.5

This CVE describes a missing authorization vulnerability in BuddyPress that allows unauthorized users to perform actions they shouldn't have access to...

Oct 22, 2025
CVE-2025-49376
7.5

This CVE describes a missing authorization vulnerability in the DELUCKS SEO WordPress plugin that allows attackers to access functionality not properl...

Oct 22, 2025
CVE-2025-30944
7.5

This CVE describes a missing authorization vulnerability in the Tablesome Table Premium WordPress plugin that allows attackers to access functionality...

Oct 22, 2025

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,010 CVEs classified as CWE-862, with 217 rated critical and 827 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free