Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5532

5532 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-10437 WPC Smart Messages for WooCommerce <= 4.2.1 - Missing Authorization to Authenticated (Subscriber+) Message Activation/Deactivation — WPC Smart Messages for WooCommerce 4.3 Medium2024-10-29
CVE-2024-50475 WordPress Signup Page plugin <= 1.0 - Arbitrary Option Update to Privilege Escalation vulnerability — Signup Page 9.8 Critical2024-10-29
CVE-2024-50476 WordPress GRÜN spendino Spendenformular plugin <= 1.0.1 - Arbitrary Option Update to Privilege Escalation vulnerability — GRÜN spendino Spendenformular 9.8 Critical2024-10-29
CVE-2024-50490 WordPress PegaPoll plugin <= 1.0.2 - Arbitrary Option Update to Privilege Escalation vulnerability — PegaPoll 9.8 Critical2024-10-29
CVE-2024-50052 Arbitrary post deletion via Playbooks /ignore-thread endpoint — Mattermost 4.3 Medium2024-10-29
CVE-2024-10008 Masteriyo LMS – eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Missing Authorization to Privilege Escalation — Masteriyo LMS – Online Course Builder for eLearning, LMS & Education 8.8 High2024-10-29
CVE-2024-9629 Contact Form 7 + Telegram <= 0.8.5 - Missing Authorization to Authenticated (Subscriber+) Subscription Approve/Pause/Refuse — Message Bridge for Contact Form 7 and Telegram 5.4 Medium2024-10-28
CVE-2024-50573 JetBrains Hub 安全漏洞 — Hub 4.3 Medium2024-10-28
CVE-2024-10402 Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and Creation — Forminator Forms – Contact Form, Payment Form & Custom Form Builder 7.5 High2024-10-26
CVE-2024-10092 Download Monitor <= 5.0.12 - Missing Authorization to API Key Manipulation — Download Monitor 4.3 Medium2024-10-26
CVE-2024-9626 Editorial Assistant by Sovrn <= 1.3.3 - Missing Authorization to Authenticated (Subscriber+) Attachment Upload and Set Post Featured Image — Editorial Assistant by Sovrn 4.3 Medium2024-10-26
CVE-2024-9584 Image Map Pro <= 6.0.20 - Missing Authorization to Authenticated (Contributor+) Map Project Add/Update/Delete — Image Map Pro – Drag-and-drop Builder for Interactive Images 5.4 Medium2024-10-25
CVE-2024-9628 WPS Telegram Chat <= 4.6.0 - Authenticated (Subscriber+) Unauthorized Access to Telegram Bot API — WPS Telegram Chat 6.3 Medium2024-10-25
CVE-2024-9630 WPS Telegram Chat <= 4.6.0 - Missing Authorization to Information Exposure — WPS Telegram Chat 5.4 Medium2024-10-25
CVE-2024-9109 UPS Live Rates and Access Points <= 2.3.12 - Missing Authorization to Plugin API key reset — Shipping Live Rates and Access Points for UPS for WooCommerce 4.3 Medium2024-10-25
CVE-2024-9686 Order Notification for Telegram <= 1.0.1 - Missing Authorization to Unauthenticated Send Telegram Test Message — Order Notification for Telegram 5.3 Medium2024-10-25
CVE-2024-49683 WordPress Schema & Structured Data for WP & AMP plugin <= 1.3.5 - Sensitive Data Exposure vulnerability — Schema & Structured Data for WP & AMP 5.3 Medium2024-10-24
CVE-2024-8667 HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce <= 2.10.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Publication — HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce 4.3 Medium2024-10-24
CVE-2024-49657 WordPress 3D Work In Progress plugin <= 1.0.3 - Arbitrary File Deletion vulnerability — 3D Work In Progress 7.7 High2024-10-23
CVE-2024-43924 WordPress Responsive Lightbox & Gallery plugin <= 2.4.7 - Broken Access Control vulnerability — Responsive Lightbox 5.3 Medium2024-10-23
CVE-2024-9583 RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 4.23.12 - Missing Authorization — RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging 4.3 Medium2024-10-23
CVE-2024-9829 Download Plugin <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) User Metadata and Comment Download — Download Plugin 6.5 Medium2024-10-23
CVE-2024-38002 Liferay Portal和Liferay DXP 安全漏洞 — Portal 9.0 Critical2024-10-22
CVE-2024-10003 Rover IDX <= 3.0.0.2903 - Authenticated (Subscriber+) Missing Authorization via Multiple Functions — Rover IDX 6.3 Medium2024-10-22
CVE-2024-49367 Nginx UI's log path can be controlled — nginx-ui 7.5AIHighAI2024-10-21
CVE-2024-49273 WordPress ProfileGrid plugin <= 5.9.3 - Cross Site Request Forgery (CSRF) vulnerability — ProfileGrid 4.3 Medium2024-10-21
CVE-2024-49293 WordPress WP VR plugin <= 8.5.4 - Broken Access Control vulnerability — WP VR 4.3 Medium2024-10-21
CVE-2024-49321 WordPress Simple Custom Post Order plugin <= 2.5.7 - Broken Access Control vulnerability — Simple Custom Post Order 4.3 Medium2024-10-21
CVE-2024-49325 WordPress Photo Gallery Builder plugin <= 3.0 - Broken Access Control to Notice Dismissal vulnerability — Photo Gallery Builder 4.3 Medium2024-10-20
CVE-2024-10078 WP Easy Post Types <= 1.4.4 - Authenticated (Subscriber+) Missing Authorization via Multiple Functions — WP Easy Post Types 6.3 Medium2024-10-18

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5532 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.