CWE-862: Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

3,029
Total CVEs
224
Critical
839
High
6.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
436
2025
1,552
2024
754
2023
138
2022
51

Top Affected Vendors

1 Google 118
2 Sap 32
3 Apple 27
4 Jenkins 22
5 Gitlab 16
6 Xwiki 12
7 Themeum 12
8 Q Free 11
9 Wpdeveloper 11
10 Apache 10

All Missing Authorization CVEs (3,029)

CVE-2024-2782
7.5

This vulnerability allows unauthenticated attackers to modify all settings of the Fluent Forms WordPress plugin via a REST API endpoint lacking proper...

May 18, 2024
CVE-2024-32724
7.5

This CVE describes a Missing Authorization vulnerability in the Sharkdropship WordPress plugin that allows unauthorized users to delete arbitrary cont...

May 14, 2024
CVE-2024-33594
7.5

This CVE describes a Missing Authorization vulnerability in the Leaky Paywall WordPress plugin that allows unauthenticated users to manipulate subscri...

Apr 29, 2024
CVE-2024-33597
7.5

This CVE describes a Missing Authorization vulnerability in the ProFaceOff SSU WordPress plugin (also known as WP S3 Smart Upload). It allows unauthor...

Apr 29, 2024
CVE-2023-44227
7.5

This CVE describes a Missing Authorization vulnerability in the Simple File List WordPress plugin that allows unauthorized file deletion. Attackers ca...

Apr 17, 2024
CVE-2024-31343
7.5

This CVE describes a Missing Authorization vulnerability in the Sonaar Music MP3 Audio Player WordPress plugin that allows unauthenticated attackers t...

Apr 10, 2024
CVE-2024-31297
7.5

This CVE describes a Missing Authorization vulnerability in the WPExperts Wholesale For WooCommerce WordPress plugin. It allows unauthenticated attack...

Apr 10, 2024
CVE-2024-31358
7.5

This CVE describes a Missing Authorization vulnerability in the WordPress plugin '5 Stars Rating Funnel' by Saleswonder.Biz. It allows unauthenticated...

Apr 10, 2024
CVE-2024-1934
7.5

This vulnerability in the WP Compress – Image Optimizer WordPress plugin allows unauthenticated attackers to reset the CDN region and set malicious ...

Apr 9, 2024
CVE-2024-27911
7.5

This vulnerability in certain Lenovo printers allows unauthenticated attackers to retrieve the administrator password. Affected organizations using vu...

Apr 5, 2024
CVE-2023-49980
7.5

This vulnerability allows unauthenticated attackers to list directories and access sensitive files in Best Student Result Management System v1.0. Anyo...

Mar 21, 2024
CVE-2024-28215
7.5

nGrinder versions before 3.5.9 have an access control vulnerability that allows attackers to create or modify webhook configurations without proper au...

Mar 7, 2024
CVE-2023-6029
7.5

The EazyDocs WordPress plugin before version 2.3.6 lacks proper authorization and CSRF protection, allowing unauthenticated attackers to delete arbitr...

Jan 15, 2024
CVE-2023-6383
7.5

The Debug Log Manager WordPress plugin before version 2.3.0 contains an unauthenticated directory listing vulnerability that allows attackers to downl...

Jan 8, 2024
CVE-2023-51650
7.5

Hertzbeat versions before 1.4.1 have Spring Boot permission misconfigurations that allow unauthenticated access to three interfaces. This vulnerabilit...

Dec 22, 2023
CVE-2023-5949
7.5

This vulnerability in the SmartCrawl WordPress plugin allows unauthorized users to access password-protected posts' content. It affects WordPress site...

Dec 18, 2023
CVE-2023-39167
7.5

CVE-2023-39167 allows unauthenticated remote attackers to access log files containing sensitive data from SENEC Storage Box devices. This affects SENE...

Dec 7, 2023
CVE-2023-30581
7.5

This vulnerability allows attackers to bypass Node.js's experimental policy mechanism by using __proto__ to require modules outside the policy.json de...

Nov 23, 2023
CVE-2023-46352
7.5

This vulnerability allows unauthenticated guests to download customer personal information from PrestaShop stores using the vulnerable Facebook conver...

Nov 2, 2023
CVE-2023-5132
7.5

The Soisy Pagamento Rateale WordPress plugin up to version 6.0.1 has an authorization bypass vulnerability that allows unauthenticated attackers to ac...

Oct 21, 2023
CVE-2023-39966
7.5

CVE-2023-39966 is an arbitrary file write vulnerability in 1Panel server management panel that allows attackers to write arbitrary files to the server...

Aug 10, 2023
CVE-2023-30195
7.5

This vulnerability allows unauthenticated attackers to download personal information in JSON format from PrestaShop stores using the vulnerable lgdeta...

Jul 6, 2023
CVE-2023-3230
7.5

This CVE describes a missing authorization vulnerability in fossbilling/fossbilling prior to version 0.5.0. It allows attackers to access functionalit...

Jun 14, 2023
CVE-2021-4339
7.5

The uListing WordPress plugin up to version 1.6.6 has an authorization bypass vulnerability in its REST API endpoint. Unauthenticated attackers can ex...

Jun 7, 2023
CVE-2020-36696
7.5

This vulnerability allows unauthenticated attackers to bypass authorization checks and download files from WooCommerce sites using the Product Input F...

Jun 7, 2023
CVE-2023-33252
7.5

CVE-2023-33252 is a cryptographic vulnerability in iden3 snarkjs that allows double spending in zero-knowledge proof systems due to insufficient valid...

May 21, 2023
CVE-2023-27963
7.5

This vulnerability allows malicious shortcuts in Apple's Shortcuts app to access sensitive user data without proper permission prompts. It affects use...

May 8, 2023
CVE-2022-48350
7.5

The HUAWEI Messaging app has a vulnerability allowing unauthorized file access, potentially exposing sensitive user data. This affects users of HUAWEI...

Mar 27, 2023
CVE-2022-48166
7.5

This vulnerability in Wavlink WL-WN530HG4 routers allows unauthenticated attackers to download configuration files and log files containing admin cred...

Feb 6, 2023
CVE-2021-33057
7.5

This vulnerability in QQ application 8.7.1 allows attackers to bypass location permission requirements and access device GPS coordinates without user ...

Jul 26, 2022
CVE-2022-1442
7.5

The Metform WordPress plugin has an access control vulnerability that allows unauthenticated attackers to retrieve all third-party API keys and secret...

May 10, 2022
CVE-2021-25002
7.5

The Tipsacarrier WordPress plugin before version 1.5.0.5 lacks authorization checks on certain functions, allowing unauthenticated attackers to access...

May 2, 2022
CVE-2022-27658
7.5

CVE-2022-27658 is an information disclosure vulnerability in SAP Innovation Management 2.0 that allows attackers to access sensitive information under...

Mar 28, 2022
CVE-2021-3814
7.5

This vulnerability in 3scale's APIdocs allows attackers to bypass access controls by using invalid tokens that trigger fallback to session authenticat...

Mar 25, 2022
CVE-2021-25087
7.5

The Download Manager WordPress plugin before version 3.2.35 has REST API endpoints without proper authorization checks, allowing unauthenticated attac...

Mar 7, 2022
CVE-2021-25093
7.5

The Link Library WordPress plugin before version 7.2.8 has an authorization vulnerability that allows unauthenticated users to delete arbitrary links ...

Feb 1, 2022
CVE-2021-24906
7.5

The Protect WP Admin WordPress plugin before version 3.6.2 contains an authorization bypass vulnerability in the lib/pwa-deactivate.php file. Unauthen...

Jan 24, 2022
CVE-2021-38789
7.5

CVE-2021-38789 is an incorrect access control vulnerability in Allwinner R818 SoC Android Q SDK V1.0 where the aw_display service fails to verify call...

Jan 19, 2022
CVE-2022-0236
7.5

This vulnerability in the WP Import Export WordPress plugin allows unauthenticated attackers to download any imported or exported data from vulnerable...

Jan 18, 2022
CVE-2021-24831
7.5

The Tab WordPress plugin before version 1.3.2 exposes all AJAX actions to unauthenticated users, allowing attackers to add, edit, or delete arbitrary ...

Jan 3, 2022
CVE-2015-20067
7.5

The WP Attachment Export WordPress plugin before version 0.2.4 lacks proper access controls, allowing unauthenticated users to download XML data conta...

Nov 1, 2021
CVE-2021-37738
7.5

CVE-2021-37738 is an information disclosure vulnerability in Aruba ClearPass Policy Manager that allows remote attackers to access sensitive informati...

Oct 15, 2021
CVE-2020-18757
7.5

CVE-2020-18757 is a vulnerability in Dut Computer Control Engineering Co.'s PLC MAC1100 that allows attackers to cause persistent denial of service vi...

Aug 13, 2021
CVE-2018-10865
7.5

CVE-2018-10865 is an authorization bypass vulnerability in Red Hat Certification 7 that allows unauthenticated users to trigger restart operations on ...

May 26, 2021
CVE-2021-20693
7.5

This vulnerability allows remote attackers to redirect users to arbitrary websites through the Gurunavi mobile app. Attackers can trick users into vis...

Apr 26, 2021
CVE-2021-28669
7.5

This vulnerability allows unauthorized users to modify configuration settings on affected Xerox multifunction printers without administrative privileg...

Mar 29, 2021
CVE-2020-29160
7.5

This vulnerability in Zammad allows attackers to modify Ticket Article data through a REST API call, bypassing auditing mechanisms. This affects all Z...

Dec 28, 2020
CVE-2020-2322
7.5

The Jenkins Chaos Monkey Plugin vulnerability allows attackers with Overall/Read permission to exploit HTTP endpoints without proper authorization che...

Dec 3, 2020
CVE-2024-11916
7.4

The WP Extended WordPress plugin has a missing capability check vulnerability that allows authenticated attackers with subscriber-level access or high...

Jan 8, 2025
CVE-2024-2544
7.4

The Popup Builder WordPress plugin has a missing capability check on all AJAX actions, allowing authenticated attackers with subscriber-level access o...

Jun 15, 2024

About Missing Authorization (CWE-862)

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Our database tracks 3,029 CVEs classified as CWE-862, with 224 rated critical and 839 rated high severity. The average CVSS score for Missing Authorization vulnerabilities is 6.3.

External reference: View CWE-862 on MITRE CWE →

Monitor Missing Authorization Vulnerabilities

Get alerted when new Missing Authorization CVEs affect your infrastructure.

Start Monitoring Free