Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-5326 Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.2 - Missing Authorization to Arbitrary Options Update — Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX 8.8 High2024-05-30
CVE-2024-4427 Comparison Slider <= 1.0.5 - Missing Authorization — Comparison Slider 4.3 Medium2024-05-30
CVE-2024-4355 Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection <= 10.23 - Missing Authorization to Information Expsoure — Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection 4.3 Medium2024-05-30
CVE-2024-4422 Comparison Slider <= 1.0.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting — Comparison Slider 6.4 Medium2024-05-30
CVE-2024-3277 Yumpu ePaper publishing <= 2.0.24 - Missing Authorization to PDF Upload, Publishing, and API Key Modification — Yumpu E-Paper publishing 5.0 Medium2024-05-30
CVE-2024-35237 MIT IdentiBot User-Kerberos Mapping Publicly Available — mit-identibot 7.5 High2024-05-27
CVE-2024-4858 Testimonial Carousel For Elementor <= 10.2.0 - Missing Authorization to Limited Setting Update — Testimonial Carousel For Elementor 5.3 Medium2024-05-25
CVE-2024-5318 Missing Authorization in GitLab — GitLab 4.0 Medium2024-05-24
CVE-2024-0893 Schema App Structured Data <= 2.2.0 - Missing Authorization — Schema App Structured Data 4.3 Medium2024-05-24
CVE-2024-3711 Brizy – Page Builder <= 2.4.43 - Missing Authorization — Brizy – Page Builder 4.3 Medium2024-05-23
CVE-2024-3626 Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.17 - Missing Authorization — Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress 4.3 Medium2024-05-23
CVE-2023-6325 RomethemeForm For Elementor <= 1.1.5 - Missing Authorization via export_entries, rtformnewform, and rtformupdate — RTMForm Builder 5.3 Medium2024-05-23
CVE-2024-20355 Cisco 多款产品安全漏洞 — Cisco Adaptive Security Appliance (ASA) Software 5.0 Medium2024-05-22
CVE-2024-2036 ApplyOnline – Application Form Builder and Manager <= 2.6.2 - Missing Authorization to Sensitive Information Exposure — ApplyOnline – Application Form Builder and Manager 4.3 Medium2024-05-22
CVE-2024-3663 WP Scraper <= 5.7 - Missing Authorization to Arbitrary Page/Post Creation — WP Scraper 4.3 Medium2024-05-22
CVE-2024-3268 YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress <= 3.3.6 - Missing Authorization to Arbitrary Post/Page Creation — Video Gallery – YouTube Gallery & Responsive Video Playlist 5.3 Medium2024-05-21
CVE-2024-4566 ShopLentor <= 2.8.8 - Missing Authorization to WordPress Option Modification — ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin 7.1 High2024-05-21
CVE-2024-4875 HT Mega – Absolute Addons For Elementor <= 2.5.2 - Missing Authorization to Options Update — HT Mega Addons for Elementor – Elementor Widgets & Template Builder 4.3 Medium2024-05-21
CVE-2024-3761 Missing Authorization on Delete Datasets in lunary-ai/lunary — lunary-ai/lunary 8.2AIHighAI2024-05-20
CVE-2024-2782 Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 7.5 High2024-05-18
CVE-2024-2771 Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation — Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 9.8 Critical2024-05-18
CVE-2024-35174 WordPress Flo Forms plugin <= 1.0.42 - Broken Access Control vulnerability — Flo Forms 5.3 Medium2024-05-17
CVE-2024-32802 WordPress Better Messages plugin <= 2.4.32 - Broken Authentication vulnerability — BP Better Messages 5.3 Medium2024-05-17
CVE-2024-32692 WordPress Chauffeur Taxi Booking System for WordPress plugin <= 6.9 - Broken Authentication vulnerability — Chauffeur Taxi Booking System for WordPress 8.2 High2024-05-17
CVE-2024-31281 WordPress Church Admin plugin <= 4.1.6 - Broken Access Control vulnerability — Church Admin 6.3 Medium2024-05-17
CVE-2023-34186 WordPress Headless CMS plugin <= 2.0.3 - Broken Authentication vulnerability — Headless CMS 5.3 Medium2024-05-17
CVE-2023-33321 WordPress EventPrime plugin <= 2.8.6 - Sensitive Data Exposure — EventPrime 5.3 Medium2024-05-17
CVE-2023-32129 WordPress Editorialmag theme <= 1.1.9 - Authenticated Arbitrary Plugin Activation — Editorialmag 4.3 Medium2024-05-17
CVE-2023-23988 WordPress My Tickets plugin <= 1.9.11 - Payment Bypass Vulnerability — My Tickets 7.5 High2024-05-17
CVE-2022-45070 WordPress Conditional Checkout Fields for WooCommerce plugin <= 1.2.3 - Broken Authentication vulnerability — Conditional Checkout Fields for WooCommerce 5.3 Medium2024-05-17

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.