VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1329 CVEsRSS

CVE-2026-18317Medium· 4.3
1w ago

The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.3

The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.3. This is due to the plugin not properly verifying tha…

▾ Sunlitfoxtheme · Foxtool All-in-One: Contact chat button, Custom login, Media optimize imagesEPSS 0.21%via NVD
CVE-2026-89007Low· 2.7
1w ago

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to delete arbitrary ap…

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to delete arbitrary ap…

▾ SunlitEPSS 0.28%via NVD
CVE-2026-84904Low· 3.8
1w ago

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and n…

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a group of image-optimization actions, gating them only on a coarse capability that lower-privileged users also hold and n…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-93455Medium· 6.5
1w ago

django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media paths

django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media paths. Attackers with low-privilege staff credentials can enumer…

▾ Sunlitbatiste · django-page-cmsEPSS 0.45%via NVD
CVE-2026-54671High· 8.8PoC
1w ago

WeGIA is a web manager for charitable institutions

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as uncondi…

▾ MidnightLabRedesCefetRJ · WeGIAEPSS 0.57%via NVD
CVE-2026-54648Medium· 6.5PoC
1w ago

CubeCart is an ecommerce software solution

CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc.php rely on page-level CC_PERM_READ access and do not require CC_PERM_DELETE for the purge, no_order_purge, or delete_guests c…

▾ Twilightcubecart · v6EPSS 0.59%via NVD
CVE-2026-54643Medium· 5.4PoC
1w ago

CubeCart is an ecommerce software solution

CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.php verifies only the presence of order_id and delete-note parameters before deleting records from CubeCart_order_notes…

▾ Twilightcubecart · v6EPSS 0.38%via NVD
CVE-2026-54608High· 7.1PoC
1w ago

MythicalDash is a Pterodactyl client area

MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/System/Gateways/Stripe.php creates a pending row in mythicaldash_stripe_payments before Stripe checkout succeeds and embed…

▾ MidnightMythicalLTD · MythicalDashEPSS 0.20%via NVD
CVE-2026-54519High· 8.8PoC
1w ago

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authenticates requests but listMemories, deleteMemory, and cle…

▾ MidnightvmDeshpande · ai-agent-automationEPSS 0.52%via NVD
CVE-2026-16750Medium· 5.3
1w ago

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, …

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, …

▾ Sunlitstylemix · Motors – Car Dealership & Classified Listings PluginEPSS 0.24%via NVD
CVE-2026-16582Medium· 5.3
1w ago

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5. This is due to the plugin accepting a client-supplied package-…

▾ Sunlitmelograno · Booking for Appointments and Events Calendar – AmeliaEPSS 0.23%via NVD
CVE-2026-14311Medium· 5.4
1w ago

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to…

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to…

▾ Sunlitmelograno · Booking for Appointments and Events Calendar – AmeliaEPSS 0.17%via NVD
CVE-2026-93378Low· 3.1
1w ago

Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file

Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.22%via NVD
CVE-2026-54237Critical· 9.3
1w ago

Wavelog is web-based amateur radio logging software

Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanit…

▾ Midnightwavelog · wavelogEPSS 0.76%via NVD
CVE-2026-92992Medium· 6.3PoC
1w ago

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to missing authoriza…

▾ TwilightDromara · mayfly-goEPSS 0.39%via NVD
CVE-2026-54677Medium· 6.5
1w ago

Scoold is a Q&A and a knowledge sharing platform for teams

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, authenticated users who are not members of a private space can create content in questions belonging to that space because src/main/java/com/erudika/scoold/cont…

▾ SunlitErudika · scooldEPSS 0.38%via NVD
CVE-2026-54676Medium· 6.5
1w ago

Scoold is a Q&A and a knowledge sharing platform for teams

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, users with personal API tokens can retrieve replies from questions in private spaces they cannot access because src/main/java/com/erudika/scoold/api/ApiControll…

▾ SunlitErudika · scooldEPSS 0.40%via NVD
CVE-2026-69197High· 8.7
1w ago

Umbraco is an ASP.NET CMS

Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the Content Delivery API applies member and Public Access checks to the directly requested node but not to referenced nodes serialized through Content Picker or Multi-Node …

▾ Twilightumbraco · Umbraco-CMSEPSS 0.66%via NVD
CVE-2026-78528Medium· 5.3
1w ago

Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.

Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.

▾ SunlitBerqWP · searchproEPSS 0.29%via NVD
CVE-2026-74017Medium· 5.3
1w ago

Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.

Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.

▾ Sunlitwpeverest · user-registrationEPSS 0.31%via NVD
CVE-2026-74002Medium· 5.3
1w ago

Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.

Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.

▾ Sunlitwpdevelop · bookingEPSS 0.29%via NVD
CVE-2026-74000Medium· 5.3
1w ago

Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.

Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.

▾ Sunlitwp.insider · simple-membershipEPSS 0.29%via NVD
CVE-2026-66676Medium· 5.3
1w ago

Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.

Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.

▾ SunlitMatrixAddons · easy-invoiceEPSS 0.31%via NVD
CVE-2026-87831Medium· 4.3
1w ago

The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitr…

The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitr…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-91010Medium· 4.3
1w ago

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests that a nonce parameter is present rather tha…

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests that a nonce parameter is present rather tha…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-91009Medium· 4.3
1w ago

The Active Woot Products Tables for WooCommerce

The Active Woot Products Tables for WooCommerce. 100% FREE  WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title …

▾ SunlitEPSS 0.14%via NVD
CVE-2026-91015Medium· 5.3
1w ago

The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowi…

The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowi…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-49292Low· 0.0
1w ago

Kiwi TCMS is an open source test management system

Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migra…

▾ Sunlitkiwitcms · KiwiEPSS 0.44%via NVD
CVE-2026-92586Medium· 4.3PoC
1w ago

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted vide…

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted vide…

▾ TwilightWWBN · AVideoEPSS 0.26%via NVD
CVE-2026-92585Medium· 4.3PoC
1w ago

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can …

▾ TwilightWWBN · AVideoEPSS 0.26%via NVD
CWE-862 vulnerabilities (CVEs) — page 9 · VulnSea