VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1329 CVEsRSS

CVE-2026-81785Medium· 6.5
2w ago

Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.

Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.

▾ SunlitThemekraft · buddyformsEPSS 0.33%via NVD
CVE-2026-78536Medium· 6.5
2w ago

Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.

Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.

▾ Sunlitrobokassa · robokassaEPSS 0.33%via NVD
CVE-2026-84821High· 7.5
2w ago

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.

▾ TwilightEpsiloncool · fulltext-searchEPSS 0.39%via NVD
CVE-2026-18594Medium· 4.3
2w ago

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This …

▾ Sunlitvsourz1td · Advanced Contact form 7 DBEPSS 0.21%via NVD
CVE-2026-88269Medium· 6.5
2w ago

GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administrative and user credentials through SSVR.

GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administrative and user credentials through SSVR.

▾ SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.34%via NVD
CVE-2026-78361Critical· 9.1
2w ago

The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing …

The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing …

▾ MidnightEPSS 0.45%via NVD
CVE-2026-77770Critical· 10.0PoC
2w ago

The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visit…

The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visit…

▾ AbyssalEPSS 0.44%via NVD
CVE-2026-87997Medium· 4.3PoC
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/chat/completions and POST /api/v1/chat/completions in backend/open_webui/main.py copied a client-supplied folder_id…

▾ Twilightopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-86765Medium· 6.5PoC
2w ago

Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint

Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint. Authenticated users with edit permission but explicitly denied checkout permission can reassign asse…

▾ Twilightsnipeitapp · snipe-itEPSS 0.40%via NVD
CVE-2026-19946Medium· 4.3
2w ago

Awesome Support <= 6.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Denial via 'user_id' Parameter

The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_…

▾ Sunlitawesomesupport · Awesome Support – WordPress HelpDesk & Support PluginEPSS 0.24%via CVEORG
CVE-2026-8615Medium· 4.3
2w ago

ilGhera Reviso Exporter for WooCommerce <= 1.2.3 - Missing Authorization to Authenticated (Subscriber+) Agreement Grant Token Deletion via disconnect_callback Function

The Reviso Exporter for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the disconnect_callback() function in versions up to, and inc…

▾ Sunlitghera74 · ilGhera Reviso Exporter for WooCommerceEPSS 0.34%via CVEORG
CVE-2026-86757Medium· 6.5
2w ago

Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea, markdown-textarea, and date/datetime picker elements

Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea, markdown-textarea, and date/datetime picker elements. Authenticated users with assets.edit, assets.checki…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.37%via NVD
CVE-2026-41869Critical· 9.1
2w ago

Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API)

Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are recommended to upgrade to version 1.2…

▾ MidnightApache Software Foundation · Apache NutchEPSS 0.72%via CVEORG
CVE-2026-87994Medium· 4.3PoC
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, the channel branch of chat_completion in backend/open_webui/main.py checked channel write access and channel membership for a …

▾ Twilightopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-41871Critical· 9.8
2w ago

Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)

Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are re…

▾ MidnightApache Software Foundation · Apache NutchEPSS 0.74%via CVEORG
CVE-2026-41870High· 8.8
2w ago

Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)

Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in…

▾ TwilightApache Software Foundation · Apache NutchEPSS 0.66%via CVEORG
CVE-2026-11821Medium· 5.4
2w ago

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.17

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.17. This is due to the plugin not properly verifying th…

▾ Sunlitarraytics · Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerceEPSS 0.18%via NVD
CVE-2026-86762High· 8.1
2w ago

Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and deactivating a user does not revoke that user's Passport personal access tokens

Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and deactivating a user does not revoke that user's Passport personal access tokens. As a result, although a d…

▾ Twilightsnipeitapp · snipe-itEPSS 0.47%via NVD
CVE-2026-86764Medium· 6.5
2w ago

Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components

Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only assets.view on the parent asset befor…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.37%via NVD
CVE-2026-86777Medium· 5.3PoC
2w ago

AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes

AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes. Attackers can access the endpoint without authentication…

▾ TwilightAlchemyCMS · alchemy_cmsEPSS 0.56%via NVD
CVE-2026-59185High· 8.5
2w ago

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

▾ Twilightidentrail · github.com/identrail/identrailvia OSV
CVE-2026-79324High· 7.5
2w ago

Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresse…

Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresse…

▾ Twilightmageplaza · gdprEPSS 0.56%via NVD
CVE-2026-68484Critical· 9.0
2w ago

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API

Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts an…

▾ MidnightSage · Sage AR AutomationEPSS 0.27%via NVD
CVE-2026-86759High· 7.1
2w ago

Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs

Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies…

▾ Twilightsnipeitapp · snipe-itEPSS 0.37%via NVD
CVE-2026-15398Medium· 4.3
2w ago

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.22

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.22. This is due to the plugin not properly verifying th…

▾ Sunlitarraytics · Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerceEPSS 0.29%via NVD
CVE-2026-85133Medium· 5.4
2w ago

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its settings AJAX actions, allowing any authenticated user, such as a subscriber, to read and destroy scan data belonging to…

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its settings AJAX actions, allowing any authenticated user, such as a subscriber, to read and destroy scan data belonging to…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-19802Medium· 4.3
2w ago

The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.5

The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.5. This is due to the plugin not properly verifying that a user is authorized to perf…

▾ Sunlitstylemix · Checkout Custom Fields Builder for WooCommerceEPSS 0.43%via NVD
CVE-2026-85132Medium· 4.3
2w ago

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule…

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule…

▾ SunlitEPSS 0.27%via NVD
CVE-2026-82848Medium· 5.3
2w ago

The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and…

The Masteriyo LMS WordPress plugin before 3.4.0 does not perform any authorization check before returning a course enrolment record over its REST API, allowing unauthenticated users to read any learner's enrolment status, timestamps and…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-82185Medium· 4.3
2w ago

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have capability or nonce checks on some of its A/B testing actions, allowing any authenticated user, such as a subscriber, to overwrite the cookie banner configuration shown…

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have capability or nonce checks on some of its A/B testing actions, allowing any authenticated user, such as a subscriber, to overwrite the cookie banner configuration shown…

▾ SunlitEPSS 0.25%via NVD
CWE-862 vulnerabilities (CVEs) — page 17 · VulnSea