VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1329 CVEsRSS

CVE-2026-86591Critical· 9.8
1w ago

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege e…

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege e…

▾ MidnightEPSS 0.54%via NVD
CVE-2026-92430Medium· 5.3
1w ago

The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a …

The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment webhook before updating an order's status, allowing unauthenticated attackers to mark a …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-92435Medium· 5.3
1w ago

The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach adm…

The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach adm…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-15660Medium· 4.3
1w ago

The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.4.7

The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.4.7. This is due to a missing capability check on the handle_oauth_callback() function which is hooked to admin_init and proc…

▾ Sunlitcleverplugins · SEO BoosterEPSS 0.20%via NVD
CVE-2026-15760Medium· 6.5
1w ago

The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including, 5.8.1 via the dnxte_get_database_tables and dnxte_get_database_data AJAX actions

The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including, 5.8.1 via the dnxte_get_database_tables and dnxte_get_database_data AJAX actions. The handlers only conditionally …

▾ SunlitDivi Essential · Divi EssentialsEPSS 0.22%via NVD
CVE-2026-89334Medium· 6.5
1w ago

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33. This is due to the plugin not properly verifying that…

▾ Sunlitwordplus · Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat BotsEPSS 0.70%via NVD
CVE-2026-88944Medium· 4.3
1w ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.8

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.8. This is due to the plugin not properly verifying that a user is authorized to pe…

▾ Sunlitthemeum · Tutor LMS – eLearning and online course solutionEPSS 0.46%via NVD
CVE-2026-93921Medium· 4.3PoC
1w ago

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read bl…

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.38%via NVD
CVE-2026-68928High· 8.6PoC
1w ago

Acode is a powerful text and code editor for Android

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and s…

▾ MidnightAcode-Foundation · AcodeEPSS 0.20%via NVD
CVE-2026-76902Medium· 5.0
1w ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, ShiroFilter configures /attachment/preview/{id} and /pic/preview/{id} as anonymous, and both routes call Att…

▾ Sunlit1Panel-dev · CordysCRMEPSS 0.27%via NVD
CVE-2026-61821High· 8.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, drop_partition_id() and drop_partition_time() use part_config.retention_schema as the target for ALTER TABLE SET SCHEMA and accept any no…

▾ Twilightpgpartman · pg_partmanEPSS 0.38%via NVD
CVE-2026-11545Low· 3.7
1w ago

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks.

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.26%via NVD
CVE-2026-82885High· 8.8
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.50%via NVD
CVE-2026-93852High· 7.1
1w ago

In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy

In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the Blazar REST …

▾ TwilightOpenStack · BlazarEPSS 0.37%via NVD
GHSA-pr6h-vr44-xq8jMedium· 5.3
1w ago

Obot: MCP Registry API readable without authentication

Obot: MCP Registry API readable without authentication

▾ Sunlitobot-platform · github.com/obot-platform/obotvia OSV
CVE-2026-77385Medium· 4.3PoC
1w ago

Kyoo is a self-hosted media server focused on movies, series, and anime

Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src…

▾ Twilightzoriya · KyooEPSS 0.34%via NVD
CVE-2026-61550Critical· 9.8
1w ago

Icinga 2 is an open source monitoring system

Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to co…

▾ MidnightIcinga · icinga2EPSS 0.67%via NVD
CVE-2026-85058High· 7.5PoC
1w ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths…

▾ Midnightmoquette · io.moquette:moquette-brokerEPSS 0.45%via NVD
GHSA-jr78-w6w5-m8f8High· 7.3
1w ago

Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks

Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks

▾ Twilightmediawiki · mediawiki/semantic-media-wikivia GHSA
CVE-2026-63199High· 8.3
1w ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the datasource creation and unsaved datasource proxy paths authorize the caller on a Datasource or GlobalDatasource scope…

▾ Twilightperses · persesEPSS 0.27%via NVD
CVE-2026-93737Medium· 6.5
1w ago

Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing authenticated users to read any project's schedule configuration

Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing authenticated users to read any project's schedule configuration. Attackers can supply arbitrary project and flow identifiers to …

▾ Sunlitazkaban · azkabanEPSS 0.54%via NVD
CVE-2026-93531Medium· 4.3PoC
1w ago

A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8

A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects unknown code. This manipulation causes cross-site request forgery. The attack may be initiated re…

▾ Twilightgedelumbung · HospitalManagementEPSS 0.23%via NVD
CVE-2026-93595Medium· 6.5
1w ago

ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI chat endpoints

ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI chat endpoints. The tool executes queries without binding the authenticated principal to DatabaseContext, causing pe…

▾ SunlitArcadeData · arcadedbEPSS 0.38%via NVD
CVE-2026-93596Medium· 4.3PoC
1w ago

ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker threads used by the parallel edge-connect phase of POST /api/v1/batch/{database}

ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker threads used by the parallel edge-connect phase of POST /api/v1/batch/{database}. Be…

▾ TwilightArcadeData · arcadedbEPSS 0.29%via NVD
CVE-2026-85410High· 8.1
1w ago

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.2. This is…

▾ Twilightpixarlabs · Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template KitsEPSS 0.58%via NVD
CVE-2026-12739Medium· 4.3
1w ago

The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0

The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is author…

▾ Sunlitsaadiqbal · WP Easy Pay – Payment and Donation Form Builder for SquareEPSS 0.34%via NVD
CVE-2026-91707Medium· 5.3
1w ago

The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.11.1

The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.11.1. This is due to the software allowing users to execute an action that does not properly validate a value before …

▾ SunlitElegant Themes · DiviEPSS 0.45%via NVD
CVE-2026-89413High· 8.1
1w ago

The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4

The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it pos…

▾ Twilightfarazfrank · Filter GalleryEPSS 0.54%via NVD
CVE-2026-89138Medium· 4.3
1w ago

The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4

The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it pos…

▾ Sunlitfarazfrank · Filter GalleryEPSS 0.39%via NVD
CVE-2026-75017Medium· 4.3
1w ago

The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.6

The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.6. This is due to t…

▾ Sunlitwpblockart · Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post GridEPSS 0.42%via NVD
CWE-862 vulnerabilities (CVEs) — page 8 · VulnSea