CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,017
Total CVEs
220
Critical
831
High
6.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
436
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 112
2 Sap 32
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Q Free 11
9 Wpdeveloper 11
10 Apache 10

All Missing Authorization CVEs (3,017)

CVE-2025-41114
7.5

An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential documents by manipulating POST paramet...

Nov 4, 2025
CVE-2025-41111
7.5

An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential information by manipulating the 'id_de...

Nov 4, 2025
CVE-2025-41112
7.5

An authorization bypass vulnerability in CanalDenuncia.app allows attackers to access other users' confidential information by manipulating the 'web' ...

Nov 4, 2025
CVE-2025-11890
7.5

This vulnerability allows unauthenticated attackers to bypass payment verification in WooCommerce stores using the Crypto Payment Gateway with Payeer ...

Nov 4, 2025
CVE-2025-62022
7.5

This CVE describes a missing authorization vulnerability in BuddyPress that allows unauthorized users to perform actions they shouldn't have access to...

Oct 22, 2025
CVE-2025-49376
7.5

This CVE describes a missing authorization vulnerability in the DELUCKS SEO WordPress plugin that allows attackers to access functionality not properl...

Oct 22, 2025
CVE-2025-30944
7.5

This CVE describes a missing authorization vulnerability in the Tablesome Table Premium WordPress plugin that allows attackers to access functionality...

Oct 22, 2025
CVE-2025-59011
7.5

This CVE describes a Missing Authorization vulnerability in the shinetheme Traveler WordPress theme that allows attackers to delete arbitrary content ...

Sep 26, 2025
CVE-2025-7664
7.5

The AL Pack WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to activate premium features by spoofing...

Aug 16, 2025
CVE-2025-54692
7.5

This CVE describes a Missing Authorization vulnerability in the WP Swings Membership For WooCommerce WordPress plugin that allows attackers to access ...

Aug 14, 2025
CVE-2025-52731
7.5

This CVE describes a Missing Authorization vulnerability in the Eventin Pro WordPress plugin (formerly WordPress Event Manager, Event Calendar and Boo...

Aug 14, 2025
CVE-2025-31425
7.5

CVE-2025-31425 is a missing authorization vulnerability in the WP Lead Capturing Pages WordPress plugin that allows attackers to delete arbitrary cont...

Aug 14, 2025
CVE-2025-30639
7.5

This CVE describes a missing authorization vulnerability in the ThemeAtelier IDonatePro WordPress plugin that allows attackers to bypass access contro...

Aug 14, 2025
CVE-2025-6253
7.5

The UiCore Elements WordPress plugin has an arbitrary file read vulnerability that allows unauthenticated attackers to read any file on the server. Th...

Aug 12, 2025
CVE-2025-7717
7.5

This CVE describes a missing authorization vulnerability in Drupal's File Download module that allows forceful browsing (unauthorized file access). At...

Jul 21, 2025
CVE-2025-52804
7.5

This CVE describes a missing authorization vulnerability in the uxper Nuss WordPress theme that allows attackers to access functionality not properly ...

Jul 16, 2025
CVE-2025-6993
7.5

The Ultimate WP Mail WordPress plugin versions 1.0.17 to 1.3.6 contain a privilege escalation vulnerability where authenticated users with Contributor...

Jul 16, 2025
CVE-2025-6814
7.5

The Booking X WordPress plugin versions 1.0 to 1.1.2 contain an authorization bypass vulnerability in the export_now() function that lacks proper capa...

Jul 4, 2025
CVE-2025-5282
7.5

The WP Travel Engine plugin for WordPress has an unauthenticated data deletion vulnerability. Attackers can delete arbitrary posts without authenticat...

Jun 13, 2025
CVE-2025-48784
7.5

A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System allows remote attackers to modify system settings without pro...

Jun 6, 2025
CVE-2025-47558
7.5

This CVE describes a Missing Authorization vulnerability in the MapSVG WordPress plugin that allows attackers to access functionality not properly res...

May 23, 2025
CVE-2025-39451
7.5

CVE-2025-39451 is a missing authorization vulnerability in Crocoblock's JetBlocks For Elementor WordPress plugin that allows attackers to access funct...

May 19, 2025
CVE-2025-39447
7.5

This CVE describes a missing authorization vulnerability in the Crocoblock JetElements For Elementor WordPress plugin. It allows attackers to access f...

May 19, 2025
CVE-2024-12812
7.5

This vulnerability in the WP ERP WordPress plugin allows employees to access terminated employees' data by manipulating parameters. It affects WordPre...

May 15, 2025
CVE-2021-47662
7.5

This vulnerability allows unauthenticated remote attackers to trigger a shutdown button via HTTPS connections, causing denial of service. Any system r...

Apr 24, 2025
CVE-2025-1021
7.5

A missing authorization vulnerability in synocopy allows remote attackers to read arbitrary files on Synology DiskStation Manager systems. This affect...

Apr 23, 2025
CVE-2025-26953
7.5

This CVE describes a Missing Authorization vulnerability in the JetMenu WordPress plugin that allows attackers to access functionality not properly re...

Apr 15, 2025
CVE-2025-27008
7.5

This CVE describes a broken access control vulnerability in the Unlimited Timeline WordPress plugin that allows unauthorized users to access functiona...

Apr 15, 2025
CVE-2025-30716
7.5

This vulnerability in Oracle E-Business Suite's CRM User Management Framework allows unauthenticated attackers to remotely access sensitive data via H...

Apr 15, 2025
CVE-2025-32929
7.5

A missing authorization vulnerability in the Barcode Generator for WooCommerce WordPress plugin allows attackers to delete arbitrary content without p...

Apr 15, 2025
CVE-2025-26942
7.5

This CVE describes a missing authorization vulnerability in the JetTricks WordPress plugin that allows attackers to access functionality not properly ...

Apr 15, 2025
CVE-2025-26958
7.5

This CVE describes a missing authorization vulnerability in the JetBlog WordPress plugin that allows attackers to access functionality not properly re...

Apr 15, 2025
CVE-2025-31909
7.5

A missing authorization vulnerability in Apptivo Business Site CRM WordPress plugin allows attackers to delete arbitrary content without proper authen...

Apr 3, 2025
CVE-2025-30880
7.5

This CVE describes a missing authorization vulnerability in JoomSky JS Help Desk WordPress plugin that allows attackers to bypass access controls and ...

Apr 1, 2025
CVE-2025-30797
7.5

This CVE describes a Missing Authorization vulnerability in the WordPress Greek Multi Tool plugin that allows attackers to bypass access controls. It ...

Apr 1, 2025
CVE-2025-30855
7.5

This vulnerability allows attackers to bypass authorization controls in the Ads by WPQuads WordPress plugin, potentially accessing administrative func...

Mar 31, 2025
CVE-2024-8999
7.5

This vulnerability in lunary-ai/lunary allows any user to export the entire database to Google BigQuery without proper authentication or authorization...

Mar 20, 2025
CVE-2025-30107
7.5

This vulnerability in IROAD V9 dashcams allows unauthorized users to modify device settings, disable critical functions, and turn off battery protecti...

Mar 18, 2025
CVE-2024-13468
7.5

The Trash Duplicate and 301 Redirect WordPress plugin has an authorization vulnerability that allows unauthenticated attackers to delete any posts or ...

Feb 19, 2025
CVE-2025-22657
7.5

This CVE describes a missing authorization vulnerability in the Atarim WordPress plugin that allows attackers to delete arbitrary content without prop...

Feb 18, 2025
CVE-2024-12269
7.5

This vulnerability allows unauthenticated attackers to download the entire WordPress database through the Safe Ai Malware Protection plugin. Any WordP...

Jan 30, 2025
CVE-2025-22717
7.5

This CVE describes a missing authorization vulnerability in the My Tickets WordPress plugin that allows attackers to access functionality not properly...

Jan 21, 2025
CVE-2025-22318
7.5

This CVE describes a Missing Authorization vulnerability in the Standard Box Sizes plugin for WooCommerce that allows unauthorized users to perform ac...

Jan 21, 2025
CVE-2024-57757
7.5

CVE-2024-57757 is an authentication bypass vulnerability in JeeWMS that allows attackers to bypass permission checks in the AuthInterceptor component....

Jan 15, 2025
CVE-2024-11423
EPSS 32.2% 7.5

This vulnerability allows unauthenticated attackers to manipulate gift card balances in WooCommerce stores using the Ultimate Gift Cards plugin. Attac...

Jan 8, 2025
CVE-2025-22592
7.5

This CVE describes a missing authorization vulnerability in the Lenderd 1003 Mortgage Application WordPress plugin that allows attackers to access fun...

Jan 7, 2025
CVE-2023-47648
7.5

A missing authorization vulnerability in the EazyDocs WordPress plugin allows attackers to bypass access controls and potentially modify or access res...

Jan 2, 2025
CVE-2023-47693
7.5

This vulnerability allows attackers to bypass authorization controls in the Ultimate Addons for Contact Form 7 WordPress plugin, potentially accessing...

Jan 2, 2025
CVE-2023-47224
7.5

This CVE describes a missing authorization vulnerability in the WP Travel WordPress plugin that allows attackers to exploit incorrectly configured acc...

Jan 2, 2025
CVE-2024-56008
7.5

This CVE describes a Missing Authorization vulnerability in the Spreadr Woocommerce WordPress plugin that allows attackers to access functionality not...

Dec 18, 2024

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,017 CVEs classified as CWE-862, with 220 rated critical and 831 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.2.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free