VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1328 CVEsRSS

CVE-2026-93344Medium· 6.5
5d ago

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_content AJAX action that allows authenticated attackers with subscriber-level access or higher to access arbitrary ve…

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_content AJAX action that allows authenticated attackers with subscriber-level access or higher to access arbitrary ve…

▾ SunlitWebWizards · MarketKingEPSS 0.43%via NVD
CVE-2026-95671Medium· 5.3
5d ago

In MISP, the CollectionsController add() method enforced the sharing-group usability authorization check and element capture only when the HTTP request method was POST

In MISP, the CollectionsController add() method enforced the sharing-group usability authorization check and element capture only when the HTTP request method was POST. However, the underlying CRUDComponent::add() method persists data on…

▾ SunlitMISP · MISPEPSS 0.37%via NVD
CVE-2026-93341Medium· 4.3
5d ago

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_send_refund AJAX action that allows authenticated attackers with subscriber-level access or higher to create refund requests a…

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_send_refund AJAX action that allows authenticated attackers with subscriber-level access or higher to create refund requests a…

▾ SunlitWebWizards · MarketKingEPSS 0.33%via NVD
CVE-2026-93342Medium· 5.4
5d ago

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_duplicate_product AJAX action that allows authenticated attackers with subscriber-level access or higher to duplicate any vend…

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_duplicate_product AJAX action that allows authenticated attackers with subscriber-level access or higher to duplicate any vend…

▾ SunlitWebWizards · MarketKingEPSS 0.32%via NVD
CVE-2026-93343Medium· 6.5
5d ago

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action that allows authenticated attackers with subscriber-level access or higher to retrieve the comp…

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action that allows authenticated attackers with subscriber-level access or higher to retrieve the comp…

▾ SunlitWebWizards · MarketKingEPSS 0.40%via NVD
CVE-2025-14486Medium· 5.3
5d ago

The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks in all versions up to, and including, 1.0.2

The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to delete arbitrary A…

▾ Sunlitkamleshyadav · PixelPlayEPSS 0.23%via NVD
CVE-2025-14484Medium· 5.3
5d ago

The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization checks in all versions up to, and including, 1.0.3

The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization checks in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to modify arbitr…

▾ Sunlitkamleshyadav · Image BuzzEPSS 0.23%via NVD
CVE-2026-91092Medium· 4.3
5d ago

The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5

The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possi…

▾ Sunlittomdever · wpForo ForumEPSS 0.39%via NVD
CVE-2026-18345Medium· 4.3
5d ago

The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Connect::complete() function in versions up to, and including, 2.9.18

The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Connect::complete() function in versions up to, and including, 2.9.18. The function is registered on the…

▾ Sunlitwpusermanager · WP User Manager – User Profile Builder & MembershipEPSS 0.20%via NVD
CVE-2026-4123Medium· 4.3
5d ago

The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.3.13

The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.3.13. This is due to a missing capability check on the toggle_cache() function which is hooked to the wp_a…

▾ Sunlitrwelephant01 · RW Elephant Rental InventoryEPSS 0.35%via NVD
CVE-2025-14487Medium· 5.3
5d ago

The Handily plugin for WordPress is vulnerable to unauthorized payment settings modification due to missing authorization checks in all versions up to, and including, 1.0.3

The Handily plugin for WordPress is vulnerable to unauthorized payment settings modification due to missing authorization checks in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to modify …

▾ Sunlitkamleshyadav · HandilyEPSS 0.23%via NVD
CVE-2026-7622Medium· 4.3
5d ago

The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1

The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is due to missing capability checks and nonce verification in the send_deactivation_survey() function registered via the…

▾ Sunlitcodexpert · ThumbPress – Compress Images, Manage Thumbnails, Detect Image Issues, WebP/AVIF, Lazy Loading, Hotlinking & MoreEPSS 0.35%via NVD
CVE-2026-77520Medium· 5.4
6d ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal user in the same workspace can obtain another user's application_id from the homepage application question-ranking endpoint when the published victi…

▾ Sunlit1Panel-dev · MaxKBEPSS 0.23%via NVD
CVE-2026-77518Medium· 5.0PoC
6d ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows another user's active MCP tool_id in the same workspace can retrieve the hidden tool through the tool-detail route because …

▾ Twilight1Panel-dev · MaxKBEPSS 0.27%via NVD
CVE-2026-77525Medium· 4.2PoC
6d ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, management chat-record routes authorize the path application_id but load records using global chat_id and chat_record_id values without confirming that the c…

▾ Twilight1Panel-dev · MaxKBEPSS 0.19%via NVD
CVE-2026-77516Medium· 5.4
6d ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member denied access to a tool by WorkspaceUserResourcePermission can still bind its identifier through tool_ids, skill_tool_i…

▾ Sunlit1Panel-dev · MaxKBEPSS 0.28%via NVD
CVE-2026-77517Medium· 5.4PoC
6d ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph operate routes authorize only knowledge_id in the request path, then query the target Document by document_id or Paragraph…

▾ Twilight1Panel-dev · MaxKBEPSS 0.23%via NVD
CVE-2026-91167Medium· 6.0
6d ago

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.28.4, PUT /@warpgate/admin/api/users/:id/roles/:role_id reaches api_update_user_role in warpgate-admin/src/api/users.rs through AdminContext but does not …

▾ Sunlitwarp-tech · warpgateEPSS 0.41%via NVD
CVE-2026-63330High· 7.7PoC
6d ago

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session aut…

▾ Midnightwarp-tech · warpgateEPSS 0.45%via NVD
CVE-2026-61748Medium· 4.3
6d ago

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and LabelPrint at POST /api/report/label/print/ require authentication but do not call users.permissions.check_user_permissio…

▾ Sunlitinventree · InvenTreeEPSS 0.42%via NVD
CVE-2026-61746Medium· 5.3PoC
6d ago

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and PluginSettingDetail set GlobalSettingsPermissions without the IsAuthenticated permission used by the project default an…

▾ Twilightinventree · InvenTreeEPSS 0.40%via NVD
CVE-2026-94411High· 8.8PoC
6d ago

jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles

jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST request with type=UserRole, their own us…

▾ Midnightjishenghua · jshERPEPSS 0.52%via NVD
CVE-2026-94412High· 8.8PoC
6d ago

jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password

jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password. Attackers can submit a request with an arbitrary target user ID to …

▾ Midnightjishenghua · jshERPEPSS 0.55%via NVD
CVE-2026-94496High· 8.3PoC
6d ago

jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles

jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles. Attackers can exploit the /role/update and /role/delete endpoints to esca…

▾ Midnightjishenghua · jshERPEPSS 0.46%via NVD
CVE-2026-94495High· 7.1PoC
6d ago

jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration

jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration. Attackers can rewrite or delete tenant-wide settings covering co…

▾ Midnightjishenghua · jshERPEPSS 0.44%via NVD
CVE-2026-94414Medium· 5.4PoC
6d ago

jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions

jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions. Attackers can supply arbitrary roleId and btnStr parameter…

▾ Twilightjishenghua · jshERPEPSS 0.38%via NVD
CVE-2026-94501High· 8.8PoC
6d ago

jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks

jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks. Attackers can manipul…

▾ Midnightjishenghua · jshERPEPSS 0.55%via NVD
CVE-2026-69190Medium· 6.3
6d ago

Graylog is a free and open log management platform

Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards permits a user with edit permission but without entity ownership to include a shareReque…

▾ SunlitGraylog2 · graylog2-serverEPSS 0.42%via NVD
CVE-2026-61745Medium· 4.3PoC
6d ago

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ endpoint in src/backend/InvenTree/machine/api.py uses IsAuthenticatedOrReadScope without requiring the ADMIN role used by other …

▾ Twilightinventree · InvenTreeEPSS 0.43%via NVD
CVE-2026-48974Medium· 5.4
6d ago

HomeBox is a home inventory and organization system

HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, ta…

▾ Sunlitsysadminsmedia · homeboxEPSS 0.29%via NVD
CWE-862 vulnerabilities (CVEs) — page 6 · VulnSea