VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1332 CVEsRSS

CVE-2026-33229Critical· 9.8PoC
5mo ago

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the…

▾ Abyssalxwiki · xwikiEPSS 1.2%via NVD
CVE-2026-2263Medium· 5.3
5mo ago

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hustle_module_converted' AJAX action in all versions up to, a…

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hustle_module_converted' AJAX action in all versions up to, a…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-4277Critical· 9.8
5mo ago

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported D…

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported D…

▾ Midnightdjangoproject · djangoEPSS 0.60%via NVD
CVE-2024-14032High· 7.8
5mo ago

Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that allows local attackers to execute arbitrary code as root by exploiting an unprotected XPC service

Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that allows local attackers to execute arbitrary code as root by exploiting an unprotected XPC service. Attackers can invo…

▾ Twilighttwitch · twitch_studioEPSS 0.18%via NVD
CVE-2026-3524High· 8.8
5mo ago

Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API …

Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API …

▾ Twilightmattermost · legal_holdEPSS 0.42%via NVD
CVE-2026-5624Medium· 4.3
5mo ago

A security flaw has been discovered in ProjectSend r2002

A security flaw has been discovered in ProjectSend r2002. This vulnerability affects unknown code of the file upload.php. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit …

▾ SunlitEPSS 0.23%via NVD
CVE-2026-3445High· 7.1
5mo ago

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, …

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, …

▾ TwilightEPSS 0.31%via NVD
CVE-2026-2826Medium· 4.3
5mo ago

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user has the `…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-25742Medium· 5.3
5mo ago

Zulip is an open-source team collaboration tool

Zulip is an open-source team collaboration tool. Prior to version 11.6, Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, even after spectator access (enable_spectator_access / WEB_PUBLIC_STREAMS…

▾ Sunlitzulip · zulipEPSS 0.45%via NVD
CVE-2026-22663High· 7.5
5mo ago

prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate checks across API endpoints and page metadata generation that allow unauthorized users to access sensitive data associat…

prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate checks across API endpoints and page metadata generation that allow unauthorized users to access sensitive data associat…

▾ Twilightfka · prompts.chatEPSS 0.28%via NVD
CVE-2026-20155High· 8.0
6mo ago

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to …

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to …

▾ Twilightcisco · evolved_programmable_network_managerEPSS 0.27%via NVD
CVE-2026-4818Medium· 6.8
6mo ago

In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.

In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.

▾ Sunlitsearch-guard · flxEPSS 0.33%via NVD
CVE-2026-21716Low· 3.3
6mo ago

An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were correctly pa…

An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were correctly pa…

▾ Sunlitnodejs · node.jsEPSS 0.15%via NVD
CVE-2026-56341High· 7.5
6mo ago

AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

▾ Twilightwwbn · wwbn/avideoEPSS 0.46%via GHSA
CVE-2026-24369High· 7.1
6mo ago

Missing Authorization vulnerability in ThemeOne The Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Grid: from n/a through 2.8.0.

Missing Authorization vulnerability in ThemeOne The Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Grid: from n/a through 2.8.0.

▾ TwilightEPSS 0.31%via NVD
CVE-2026-22172Critical· 9.9
6mo ago

OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections

OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. …

▾ MidnightOpenClaw · OpenClawEPSS 0.56%via CVEORG
CVE-2026-27608High· 8.1
7mo ago

Parse Dashboard is a standalone dashboard for managing Parse Server apps

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) does not enforce authorization. Authenticated users scoped …

▾ TwilightEPSS 0.38%via NVD
CVE-2025-70141Critical· 9.4PoC
7mo ago

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php bas…

▾ Abyssaloretnom23 · customer_support_systemEPSS 0.69%via NVD
CVE-2025-70147High· 7.5PoC
7mo ago

Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET …

Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET …

▾ Midnightprojectworlds · online_time_table_generatorEPSS 0.52%via NVD
CVE-2025-70146Critical· 9.1PoC
7mo ago

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting reco…

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting reco…

▾ Abyssalprojectworlds · online_time_table_generatorEPSS 0.57%via NVD
CVE-2025-70150Critical· 9.8PoC
7mo ago

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.

▾ Abyssalcodeastro · membership_management_systemEPSS 0.66%via NVD
CVE-2025-70148High· 7.5PoC
7mo ago

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated…

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated…

▾ Midnightcodeastro · membership_management_systemEPSS 0.43%via NVD
CVE-2025-14843Medium· 5.3
8mo ago

The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in all versions up to, and including, 1.3.1

The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in all versions up to, and including, 1.3.1. This is due to a lack of authentication and authorization checks in the 'ha…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-24368Medium· 5.3
8mo ago

Missing Authorization vulnerability in ThemeOne The Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Grid: from n/a through 2.8.0.

Missing Authorization vulnerability in ThemeOne The Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Grid: from n/a through 2.8.0.

▾ SunlitEPSS 0.21%via NVD
CVE-2025-13772High· 7.1
8mo ago

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorize…

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorize…

▾ Twilightgitlab · gitlabEPSS 0.43%via NVD
CVE-2025-12449Medium· 5.4
8mo ago

The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive information due to missing capability checks on multiple AJAX actions in all versions up to, and…

The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive information due to missing capability checks on multiple AJAX actions in all versions up to, and…

▾ Sunlitkodezen · aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation BuilderEPSS 0.25%via NVD
CVE-2025-15115Medium· 6.5
8mo ago

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any user account by exploiting OAuth token validation flaws in the social login syst…

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any user account by exploiting OAuth token validation flaws in the social login syst…

▾ Sunlitpetlibro · petlibroEPSS 0.30%via NVD
CVE-2025-34171Medium· 5.3PoC
8mo ago

CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retrieve sensitive configuration files and system debug information

CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retrieve sensitive configuration files and system debug information. The /v1/users/image endpoint can be abused with a us…

▾ Twilighticewhale · casaosEPSS 0.64%via NVD
CVE-2025-62115Medium· 4.3
9mo ago

Missing Authorization vulnerability in ThemeBoy Hide Plugins hide-plugins allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hide Plugins: from n/a through <= 1.0.4.

Missing Authorization vulnerability in ThemeBoy Hide Plugins hide-plugins allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hide Plugins: from n/a through <= 1.0.4.

▾ SunlitEPSS 0.22%via NVD
CVE-2025-62751Medium· 4.3
9mo ago

Missing Authorization vulnerability in extendthemes Vireo vireo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vireo: from n/a through <= 1.0.24.

Missing Authorization vulnerability in extendthemes Vireo vireo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vireo: from n/a through <= 1.0.24.

▾ Sunlitextendthemes · vireoEPSS 0.21%via NVD
CWE-862 vulnerabilities (CVEs) — page 42 · VulnSea