Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5532

5532 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-59022 TYPO3 CMS Allows Broken Access Control in Recycler Module — TYPO3 CMS 8.1AIHighAI2026-01-13
CVE-2025-59021 TYPO3 CMS Allows Broken Access Control in Redirects Module — TYPO3 CMS 4.6AIMediumAI2026-01-13
CVE-2025-14001 WP Duplicate Page <= 1.8 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Duplication — WP Duplicate Page 5.4 Medium2026-01-13
CVE-2026-0511 Multiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation) — SAP Fiori App (Intercompany Balance Reconciliation) 8.1 High2026-01-13
CVE-2026-0506 Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform — SAP NetWeaver Application Server ABAP and ABAP Platform 8.1 High2026-01-13
CVE-2026-0503 Missing Authorization check in in SAP ERP Central Component and SAP S/4HANA (SAP EHS Management) — SAP ERP Central Component and SAP S/4HANA (SAP EHS Management) 6.4 Medium2026-01-13
CVE-2026-0497 Missing Authorization check in Business Server Pages Application (Product Designer Web UI) — Business Server Pages Application (Product Designer Web UI) 4.3 Medium2026-01-13
CVE-2025-14948 miniOrange OTP Verification and SMS Notification for WooCommerce <= 4.3.8 - Missing Authorization to Unauthenticated Notification Settings Modification — miniOrange OTP Verification and SMS Notification for WooCommerce 5.3 Medium2026-01-10
CVE-2026-0817 CampaignEvents API missing authorization exposes meeting and chat URLs — MediaWiki - CampaignEvents extension 8.8 -2026-01-09
CVE-2025-14172 WP Page Permalink Extension <= 1.5.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Rewrite Rules Flush — WP Page Permalink Extension 6.5 Medium2026-01-09
CVE-2025-13717 Contact Form vCard Generator <= 2.4 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'wp-gvc-cf-download-id' Parameter — Contact Form vCard Generator 5.3 Medium2026-01-09
CVE-2025-13772 Missing Authorization in GitLab — GitLab 7.1 High2026-01-09
CVE-2025-13781 Missing Authorization in GitLab — GitLab 6.5 Medium2026-01-09
CVE-2025-14657 Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) <= 4.0.51 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via 'post_settings' — Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) 7.2 High2026-01-09
CVE-2025-13934 Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Course Enrollment Bypass — Tutor LMS – eLearning and online course solution 4.3 Medium2026-01-09
CVE-2025-13935 Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Course Completion — Tutor LMS – eLearning and online course solution 4.3 Medium2026-01-09
CVE-2025-14741 Frontend Admin by DynamiApps <= 3.28.25 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via 'delete post' Form Element — Frontend Admin by DynamiApps 9.1 Critical2026-01-09
CVE-2025-13628 Tutor LMS – eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Coupon Modification — Tutor LMS – eLearning and online course solution 4.3 Medium2026-01-09
CVE-2025-14146 Booking Calendar <= 10.14.10 - Unauthenticated Sensitive Information Exposure — Booking Calendar 5.3 Medium2026-01-09
CVE-2025-14718 Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories <= 4.9.3 - Missing Authorization to Authenticated (Contributor+) Workflow Manipulation — Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories 5.4 Medium2026-01-09
CVE-2025-14720 Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions — Booking for Appointments and Events Calendar – Amelia 5.3 Medium2026-01-09
CVE-2025-14782 Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.49.1 - Missing Authorization to Authenticated (Forminator User+) CSV Export — Forminator Forms – Contact Form, Payment Form & Custom Form Builder 5.3 Medium2026-01-09
CVE-2025-14886 Japanized for WooCommerce <= 2.7.17 - Missing Authorization to Unauthenticated Order Status Modification — Japanized for WooCommerce 5.3 Medium2026-01-09
CVE-2026-22486 WordPress Re Gallery plugin <= 1.18.9 - Broken Access Control vulnerability — Re Gallery 5.3 Medium2026-01-08
CVE-2026-22487 WordPress Speed Kit plugin <= 2.0.2 - Broken Access Control vulnerability — Speed Kit 4.3 Medium2026-01-08
CVE-2026-22488 WordPress Dashboard Welcome for Beaver Builder plugin <= 1.0.8 - Broken Access Control vulnerability — Dashboard Welcome for Beaver Builder 5.3 Medium2026-01-08
CVE-2026-22490 WordPress Bulk Landing Page Creator for WordPress LPagery plugin <= 2.4.9 - Broken Access Control vulnerability — Bulk Landing Page Creator for WordPress LPagery 5.4 Medium2026-01-08
CVE-2026-22492 WordPress Docket Cache plugin <= 24.07.04 - Broken Access Control vulnerability — Docket Cache 4.3 Medium2026-01-08
CVE-2026-22517 WordPress GA4WP: Google Analytics for WordPress plugin <= 2.10.0 - Broken Access Control vulnerability — GA4WP: Google Analytics for WordPress 5.4 Medium2026-01-08
CVE-2026-22522 WordPress Block Slider plugin <= 2.2.3 - Broken Access Control vulnerability — Block Slider 6.5 Medium2026-01-08

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5532 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.