Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5529

5529 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-3053 Page Builder by AZEXO <= 1.27.133 - Missing Authorization to Post Creation — Page Builder with Image Map by AZEXO 5.4 Medium2023-06-02
CVE-2023-2434 Nested Pages <= 3.2.3 - Missing Authorization to Authenticated (Editor+) Plugin Settings Reset — Nested Pages 3.8 Low2023-05-31
CVE-2023-2945 Missing Authorization in openemr/openemr — openemr/openemr 6.5 -2023-05-27
CVE-2023-32316 Users can add themselves to any organization in CloudExplorer Lite — CloudExplorer-Lite 7.1 High2023-05-26
CVE-2023-32311 The CloudExplorer Lite missing permissions check — CloudExplorer-Lite 7.1 High2023-05-26
CVE-2023-33948 Liferay Portal和Liferay DXP 安全漏洞 — Portal 5.3 Medium2023-05-24
CVE-2023-2494 Go Pricing - WordPress Responsive Pricing Tables <= 3.3.19 - Missing Authorization to Limited Privilege Granting — Go Pricing - WordPress Responsive Pricing Tables 4.6 Medium2023-05-23
CVE-2023-2716 Groundhogg <= 2.7.9.8 - Missing Authorization to Non-Arbitrary File Upload — Groundhogg — CRM, Newsletters, and Marketing Automation 5.4 Medium2023-05-20
CVE-2023-2714 Groundhogg <= 2.7.9.8 - Missing Authorization to Update License — Groundhogg — CRM, Newsletters, and Marketing Automation 4.3 Medium2023-05-20
CVE-2023-2715 Groundhogg <= 2.7.9.8 - Missing Authorization to Admin Account and Ticket Creation — Groundhogg — CRM, Newsletters, and Marketing Automation 4.3 Medium2023-05-20
CVE-2023-32677 Users who can send invitations can erroneously add users to streams during invitation in Zulip — zulip 3.1 Low2023-05-19
CVE-2023-2757 Waiting: One-click countdowns <= 0.6.2 - Missing Authorization Checks leading to Authenticated (Subscriber+) Stored Cross-Site Scripting — Waiting: One-click countdowns 7.4 High2023-05-18
CVE-2023-32112 Missing Authorization Check in Vendor Master Hierarchy — Vendor Master Hierarchy 2.8 Low2023-05-09
CVE-2023-2590 Missing Authorization in answerdev/answer — answerdev/answer 8.6 -2023-05-09
CVE-2023-22728 Silverstripe Framework has missing permission check of canView in GridFieldPrintButton — silverstripe-framework 4.3 Medium2023-04-26
CVE-2023-2193 Oauth authorization codes do not expire when deauthorizing an oauth2 app — Mattermost 6.5 Medium2023-04-20
CVE-2023-25552 Schneider Electric StruxureWare Data Center Expert 安全漏洞 — StruxureWare Data Center Expert 8.1 High2023-04-18
CVE-2023-29529 matrix-js-sdk vulnerable to invisible eavesdropping in group calls — matrix-js-sdk 5.0 Medium2023-04-14
CVE-2023-1903 Missing Authorization check in SAP HCM Fiori App My Forms (Fiori 2.0) — HCM Fiori App My Forms (Fiori 2.0) 4.3 Medium2023-04-11
CVE-2023-1928 WP Fastest Cache <= 1.1.2 - Missing Authorization in 'wpfc_preload_single_callback' — WP Fastest Cache – WordPress Cache Plugin 4.3 Medium2023-04-06
CVE-2023-1929 WP Fastest Cache <= 1.1.2 - Missing Authorization in 'wpfc_purgecache_varnish_callback' — WP Fastest Cache – WordPress Cache Plugin 4.3 Medium2023-04-06
CVE-2023-1930 WP Fastest Cache <= 1.1.2 - Missing Authorization in 'wpfc_clear_cache_of_allsites_callback' — WP Fastest Cache – WordPress Cache Plugin 4.3 Medium2023-04-06
CVE-2023-1931 WP Fastest Cache <= 1.1.2 - Missing Authorization in 'deleteCssAndJsCacheToolbar' — WP Fastest Cache – WordPress Cache Plugin 4.3 Medium2023-04-06
CVE-2023-1782 Nomad Unauthenticated Client Agent HTTP Request Privilege Escalation — Nomad 10.0 Critical2023-04-05
CVE-2022-4940 WCFM Membership <= 2.10.0 - Missing Authorization — WCFM Membership – WooCommerce Memberships for Multivendor Marketplace 7.3 High2023-04-05
CVE-2022-4939 WCFM Membership <= 2.10.0 - Unauthenticated Privilege Escalation — WCFM Membership – WooCommerce Memberships for Multivendor Marketplace 9.8 Critical2023-04-05
CVE-2023-1868 YourChannel <= 1.2.3 - Missing Authorization to Plugin Cache Reset — YourChannel: Everything you want in a YouTube plugin. 6.5 Medium2023-04-05
CVE-2023-1865 YourChannel <= 1.2.3 - Missing Authorization to Plugin Settings Reset — YourChannel: Everything you want in a YouTube plugin. 6.5 Medium2023-04-05
CVE-2023-26269 Apache James server: Privilege escalation through unauthenticated JMX — Apache James server 7.8 -2023-04-03
CVE-2023-1774 Unauthorized email invite to a private channel — Mattermost 4.2 Medium2023-03-31

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5529 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.