Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5530

5530 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-15327 Tanium addressed an improper access controls vulnerability in Deploy. — Deploy 4.3 Medium2026-02-05
CVE-2025-15330 Tanium addressed an improper input validation vulnerability in Deploy. — Deploy 8.8 High2026-02-05
CVE-2025-15289 Tanium addressed an improper access controls vulnerability in Interact. — Interact 3.1 Low2026-02-05
CVE-2026-1927 GreenShift - Animation and Page Builder Blocks <= 12.6 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure of AI API Keys and Stored Cross-Site Scripting via custom_css — Greenshift – animation and page builder blocks 5.4 Medium2026-02-05
CVE-2025-14079 ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.5 - Missing Authorization to Authenticated (Subscriber+) Settings Update — ELEX WordPress HelpDesk & Customer Ticketing System 5.3 Medium2026-02-05
CVE-2025-13416 ProfileGrid – User Profiles, Groups and Communities <= 5.9.7.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Suspension — ProfileGrid – User Profiles, Groups and Communities 4.3 Medium2026-02-05
CVE-2026-1897 WeKan Position-History Tracking positionHistory.js PositionHistoryBleed authorization — WeKan 4.3 Medium2026-02-05
CVE-2026-25538 Devtron Attributes API Unauthorized Access Leading to API Token Signing Key Leakage — devtron 8.8AIHighAI2026-02-04
CVE-2026-25517 Wagtail has improper permission handling on admin preview endpoints — wagtail 5.3AIMediumAI2026-02-04
CVE-2026-0679 Fortis for WooCommerce <= 1.2.0 - Missing Authorization to Unauthenticated Arbitrary Order Status Update to Paid via 'wc-api' Endpoint — Fortis for WooCommerce 5.3 Medium2026-02-04
CVE-2026-0572 WebPurify Profanity Filter <= 4.0.2 - Missing Authorization to Unauthenticated Plugin Settings Change via webpurify_save_options — WebPurify Profanity Filter 6.5 Medium2026-02-04
CVE-2025-15507 Magic Import Document Extractor <= 1.0.5 - Missing Authorization to Unauthenticated Plugin License Status Modification — Magic Import Document Extractor 5.3 Medium2026-02-04
CVE-2025-15285 SEO Flow by LupsOnline <= 2.2.1 - Unauthenticated Arbitrary Post/Category Modification — SEO Flow by LupsOnline 7.5 High2026-02-04
CVE-2025-15260 MyRewards – Loyalty Points and Rewards for WooCommerce <= 5.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Loyalty Rule Modification — MyRewards 6.5 Medium2026-02-04
CVE-2025-14461 Xendit Payment <= 6.0.2 - Missing Authorization to Unauthenticated Arbitrary Order Status Update to Paid — Xendit Payment 5.3 Medium2026-02-04
CVE-2026-25036 WordPress Passster plugin <= 4.2.25 - Broken Access Control vulnerability — Passster 6.5 Medium2026-02-03
CVE-2026-25028 WordPress ElementInvader Addons for Elementor plugin <= 1.4.1 - Broken Access Control vulnerability — ElementInvader Addons for Elementor 5.4 Medium2026-02-03
CVE-2026-25021 WordPress Mizan Demo Importer plugin <= 0.1.3 - Broken Access Control vulnerability — Mizan Demo Importer 5.4 Medium2026-02-03
CVE-2026-25019 WordPress Atarim plugin <= 4.3.1 - Broken Access Control vulnerability — Atarim 5.3 Medium2026-02-03
CVE-2026-25020 WordPress WP Sync for Notion plugin <= 1.7.0 - Broken Access Control vulnerability — WP Sync for Notion 4.3 Medium2026-02-03
CVE-2026-25010 WordPress Share This Image plugin <= 2.09 - Broken Access Control vulnerability — Share This Image 5.3 Medium2026-02-03
CVE-2026-25012 WordPress WP Bannerize Pro plugin <= 1.11.0 - Broken Access Control vulnerability — WP Bannerize Pro 5.3 Medium2026-02-03
CVE-2026-25011 WordPress WP Custom Admin Interface plugin <= 7.41 - Broken Access Control vulnerability — WP Custom Admin Interface 4.3 Medium2026-02-03
CVE-2026-25016 WordPress Nelio Popups plugin <= 1.3.5 - Broken Access Control vulnerability — Nelio Popups 4.3 Medium2026-02-03
CVE-2026-24997 WordPress Wired Impact Volunteer Management plugin <= 2.8 - Broken Access Control vulnerability — Wired Impact Volunteer Management 5.3 Medium2026-02-03
CVE-2026-24996 WordPress WPElemento Importer plugin <= 0.6.4 - Broken Access Control vulnerability — WPElemento Importer 4.3 Medium2026-02-03
CVE-2026-24995 WordPress Latest Post Shortcode plugin <= 14.2.0 - Broken Access Control vulnerability — Latest Post Shortcode 4.3 Medium2026-02-03
CVE-2026-24990 WordPress WP Docs plugin <= 2.2.8 - Broken Access Control vulnerability — WP Docs 5.4 Medium2026-02-03
CVE-2026-24994 WordPress Sunshine Photo Cart plugin <= 3.5.7.2 - Broken Access Control vulnerability — Sunshine Photo Cart 5.3 Medium2026-02-03
CVE-2026-24982 WordPress Spectra plugin <= 2.19.17 - Broken Access Control vulnerability — Spectra 5.3 Medium2026-02-03

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5530 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.