Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-5816 Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship <= 3.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) View Order Tracking Details — Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship 4.3 Medium2025-07-18
CVE-2025-3871 Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlier — GoAnywhere MFT 5.3 Medium2025-07-16
CVE-2025-28965 WordPress URL Shortener <= 3.0.7 - Broken Access Control Vulnerability — URL Shortener 8.6 High2025-07-16
CVE-2025-29000 WordPress Multi-language Responsive Contact Form plugin <= 2.8 - Broken Access Control Vulnerability — Multi-language Responsive Contact Form 7.5 High2025-07-16
CVE-2025-30959 WordPress Product XML Feed Manager for WooCommerce <= 2.9.2 - Broken Access Control Vulnerability — Product XML Feed Manager for WooCommerce 6.5 Medium2025-07-16
CVE-2025-48339 WordPress Profiler - What Slowing Down Your WP <= 1.0.0 - Broken Access Control Vulnerability — Profiler - What Slowing Down Your WP 6.5 Medium2025-07-16
CVE-2025-49319 WordPress Wishlist for WooCommerce <= 3.2.3 - Broken Access Control Vulnerability — Wishlist for WooCommerce 6.5 Medium2025-07-16
CVE-2025-49888 WordPress PW WooCommerce On Sale! plugin <= 1.39 - Broken Access Control Vulnerability — PW WooCommerce On Sale! 7.1 High2025-07-16
CVE-2025-49884 WordPress Internal Linking of Related Contents plugin <= 1.1.8 - Broken Access Control Vulnerability — Internal Linking of Related Contents 6.5 Medium2025-07-16
CVE-2025-50028 WordPress Ultimate Push Notifications plugin <= 1.2.0 - Broken Access Control Vulnerability — Ultimate Push Notifications 6.5 Medium2025-07-16
CVE-2025-52804 WordPress Nuss theme <= 1.3.7.1 - Broken Access Control Vulnerability — Nuss 7.5 High2025-07-16
CVE-2025-52803 WordPress Sala theme <= 1.1.3 - Broken Access Control Vulnerability — Sala 7.5 High2025-07-16
CVE-2025-48150 WordPress Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin plugin <= 4.48 - Broken Access Control Vulnerability — Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin 4.3 Medium2025-07-16
CVE-2025-48155 WordPress Residential Address Detection plugin <= 2.5.9 - Broken Access Control Vulnerability — Residential Address Detection 5.3 Medium2025-07-16
CVE-2025-48166 WordPress Stop and Block bots plugin Anti bots <= 1.48 - Broken Access Control Vulnerability — Stop and Block bots plugin Anti bots 5.3 Medium2025-07-16
CVE-2025-48167 WordPress Chatbox Manager plugin <= 1.2.5 - Broken Access Control Vulnerability — Chatbox Manager 5.4 Medium2025-07-16
CVE-2025-54047 WordPress Cost Calculator plugin <= 7.4 - Broken Access Control Vulnerability — Cost Calculator 4.3 Medium2025-07-16
CVE-2025-54037 WordPress News Kit Elementor Addons plugin <= 1.3.4 - Broken Access Control Vulnerability — News Kit Elementor Addons 5.4 Medium2025-07-16
CVE-2025-54018 WordPress CM Pop-Up banners plugin <= 1.8.4 - Broken Access Control Vulnerability — CM Pop-Up banners 4.3 Medium2025-07-16
CVE-2025-54011 WordPress SMTP2GO plugin <= 1.12.1 - Broken Access Control Vulnerability — SMTP2GO 4.3 Medium2025-07-16
CVE-2025-53997 WordPress Houzez theme <= 4.0.4 - Broken Access Control Vulnerability — Houzez 4.3 Medium2025-07-16
CVE-2025-53986 WordPress Hestia theme <= 3.2.10 - Broken Access Control Vulnerability — Hestia 5.3 Medium2025-07-16
CVE-2025-6993 Ultimate WP Mail 1.0.17 - 1.3.6 - Missing Authorization to Authenticated (Contributor+) Privilege Escalation via get_email_log_details Function — Ultimate WP Mail 7.5 High2025-07-16
CVE-2025-6043 Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal <= 17.0 - Authenticated (Subscriber+) Arbitrary File Deletion — Malcure Malware Shield — Removal, Repair, Monitor 8.1 High2025-07-16
CVE-2025-49829 Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) missing validations — conjur 8.1AIHighAI2025-07-15
CVE-2025-53959 JetBrains YouTrack 安全漏洞 — YouTrack 7.6 High2025-07-15
CVE-2025-5394 Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation — Alone – Charity Multipurpose Non-profit WordPress Theme 9.8 Critical2025-07-15
CVE-2025-53825 Dokploy's Preview Deployments are vulnerable to Remote Code Execution — dokploy 9.4 Critical2025-07-14
CVE-2025-52954 Junos OS Evolved: A low-privileged user can execute arbitrary Junos commands and modify the configuration, thereby compromising the system — Junos OS Evolved 7.8 High2025-07-11
CVE-2025-52950 Juniper Security Director: Insufficient authorization for multiple endpoints in web interface — Juniper Security Director 9.6 Critical2025-07-11

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.