Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-12937 ACF Flexible Layouts Manager <= 1.1.6 - Missing Authorization to Unauthenticated Custom Field Update — ACF Flexible Layouts Manager 6.5 Medium2025-11-18
CVE-2025-11620 Multiple Roles per User <= 1.0 - Missing Authorization to Authenticated (Custom+) Privilege Escalation — Multiple Roles per User 7.2 High2025-11-18
CVE-2025-6171 Missing Authorization in GitLab — GitLab 5.3 Medium2025-11-15
CVE-2025-12849 Contest Gallery <= 28.0.2 - Missing Authorization — Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe 5.3 Medium2025-11-15
CVE-2025-12847 All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.8.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Deletion — All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic 4.3 Medium2025-11-15
CVE-2025-12817 PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege — PostgreSQL 3.1 Low2025-11-13
CVE-2025-12377 Gallery Plugin for WordPress – Envira Photo Gallery <= 1.12.0 - Missing Authorization to Authenticated (Author+) Multiple Gallery Actions — Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More 4.3 Medium2025-11-13
CVE-2025-64384 WordPress JetFormBuilder plugin <= 3.5.3 - Broken Access Control vulnerability — JetFormBuilder 5.3 Medium2025-11-13
CVE-2025-64382 WordPress Order Export & Order Import for WooCommerce plugin <= 2.6.7 - Broken Access Control vulnerability — Order Export & Order Import for WooCommerce 4.3 Medium2025-11-13
CVE-2025-64379 WordPress Booster for WooCommerce plugin <= 7.4.0 - Broken Access Control vulnerability — Booster for WooCommerce 4.3 Medium2025-11-13
CVE-2025-64370 WordPress YOP Poll plugin <= 6.5.38 - Broken Access Control vulnerability — YOP Poll 5.3 Medium2025-11-13
CVE-2025-64369 WordPress Contact Form Email plugin <= 1.3.58 - Broken Access Control vulnerability — Contact Form Email 6.5 Medium2025-11-13
CVE-2025-64276 WordPress Survey Maker plugin <= 5.1.9.4 - Broken Access Control vulnerability — Survey Maker 6.5 Medium2025-11-13
CVE-2025-64277 WordPress ChatBot plugin <= 7.3.9 - Broken Access Control vulnerability — ChatBot 5.3 Medium2025-11-13
CVE-2025-64274 WordPress WPKoi Templates for Elementor plugin <= 3.4.4 - Broken Access Control vulnerability — WPKoi Templates for Elementor 4.3 Medium2025-11-13
CVE-2025-64269 WordPress WooCommerce PDF Invoice Builder plugin <= 1.2.150 - Broken Access Control vulnerability — WooCommerce PDF Invoice Builder 4.3 Medium2025-11-13
CVE-2025-64265 WordPress Frontend File Manager plugin <= 23.2 - Broken Access Control vulnerability — Frontend File Manager 4.3 Medium2025-11-13
CVE-2025-64263 WordPress WP Content Pilot plugin <= 2.1.7 - Broken Access Control vulnerability — WP Content Pilot 5.4 Medium2025-11-13
CVE-2025-64261 WordPress Appointment Booking Calendar plugin <= 1.3.95 - Broken Access Control vulnerability — Appointment Booking Calendar 5.4 Medium2025-11-13
CVE-2025-64259 WordPress Theater for WordPress plugin <= 0.18.8 - Broken Access Control vulnerability — Theater for WordPress 5.3 Medium2025-11-13
CVE-2025-12015 Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeed <= 2.0.0 - Missing Authorization to Authenticated (Subscriber+) Afosto Disconnect — Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeed 4.3 Medium2025-11-13
CVE-2025-12891 Survey Maker <= 5.1.9.4 - Missing Authorization to Unauthenticated Information Exposure — Survey Maker 5.3 Medium2025-11-13
CVE-2025-12892 Survey Maker <= 5.1.9.4 - Missing Authorization to Unauthenticated Limited Option Update — Survey Maker 5.3 Medium2025-11-13
CVE-2025-12979 Welcart e-Commerce <= 2.11.24 - Missing Authorization to Unauthenticated Information Exposure — Welcart e-Commerce 5.3 Medium2025-11-13
CVE-2025-13063 DinukaNavaratna Dee Store authorization — Dee Store 7.3 High2025-11-12
CVE-2025-64407 Apache OpenOffice: URL fetching can be used to exfiltrate arbitrary INI file values and environment variables — Apache OpenOffice 4.0 -2025-11-12
CVE-2025-64405 Apache OpenOffice: Remote documents loaded without prompt via DDE function — Apache OpenOffice 6.2 -2025-11-12
CVE-2025-64404 Apache OpenOffice: Remote documents loaded without prompt via background and bullet images — Apache OpenOffice 6.8 -2025-11-12
CVE-2025-64403 Apache OpenOffice: Remote documents loaded without prompt via "external data sources" in Calc — Apache OpenOffice 4.0 -2025-11-12
CVE-2025-64402 Apache OpenOffice: Remote documents loaded without prompt via OLE objects — Apache OpenOffice 6.2 -2025-11-12

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.