Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-7045 Improper Access Control in open-webui/open-webui — open-webui/open-webui 5.3 -2025-03-20
CVE-2024-9096 Improper Authorization in lunary-ai/lunary — lunary-ai/lunary 4.3 -2025-03-20
CVE-2024-7046 Improper Access Control in open-webui/open-webui — open-webui/open-webui 5.3 -2025-03-20
CVE-2024-10762 Missing Authorization in lunary-ai/lunary — lunary-ai/lunary 5.4 -2025-03-20
CVE-2024-9000 Improper Authorization and Duplicate Slug Vulnerability in lunary-ai/lunary — lunary-ai/lunary 6.5 -2025-03-20
CVE-2024-2292 Access Control Vulnerabilities lead to Violation of Privacy and Modification of Personal Data — changeweb/unifiedtransform 8.1 -2025-03-20
CVE-2024-10274 Improper Authorization in lunary-ai/lunary — lunary-ai/lunary 4.3 -2025-03-20
CVE-2024-8999 Improper Access Control in lunary-ai/lunary — lunary-ai/lunary 5.3 -2025-03-20
CVE-2024-9095 Improper Authorization in lunary-ai/lunary — lunary-ai/lunary 8.1 -2025-03-20
CVE-2024-13060 Improper Authorization in mintplex-labs/anything-llm — mintplex-labs/anything-llm 4.3 -2025-03-20
CVE-2025-1766 Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Missing Authorization to Unauthenticated Payment Status Update — Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) 5.3 Medium2025-03-20
CVE-2024-12920 FoodBakery | Delivery Restaurant Directory WordPress Theme <= 4.7 - Missing Authorization in Multiple Functions — FoodBakery | Delivery Restaurant Directory WordPress Theme 8.8 High2025-03-19
CVE-2024-13412 CozyStay <= 1.7.0 - Missing Authorization to Arbitrary Action Execution in ajax_handler — CozyStay - Hotel Booking WordPress Theme 7.5 High2025-03-19
CVE-2024-12922 Altair <= 5.2.4 - Unauthenticated Arbitrary Options Update via pp_import_current — Altair 9.8 Critical2025-03-19
CVE-2025-2290 LifterLMS <= 8.0.1 - Missing Authorization to Unauthenticated Post Trashing — LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes 5.3 Medium2025-03-19
CVE-2025-2262 Logo Slider <= 3.7.3 - Unauthenticated Arbitrary Shortcode Execution — Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation 7.3 High2025-03-18
CVE-2025-26961 WordPress Fresh Framework plugin <= 1.70.0 - Unauthenticated Broken Access Control vulnerability — Fresh Framework 8.6 High2025-03-15
CVE-2025-26969 WordPress PrivateContent plugin <= 8.11.5 - Subscriber+ Site Wide Broken Access Control vulnerability — PrivateContent 8.3 High2025-03-15
CVE-2025-2025 Give <= 3.22.0 - Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings Function — GiveWP – Donation Plugin and Fundraising Platform 6.5 Medium2025-03-15
CVE-2025-1668 School Management System – WPSchoolPress <= 2.2.16 - Missing Authorization to Arbitrary User Deletion — School Management System – WPSchoolPress 4.3 Medium2025-03-15
CVE-2024-12336 WC Affiliate – A Complete WooCommerce Affiliate Plugin <= 2.5.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via wf-export-all — WC Affiliate – WooCommerce Affiliate Plugin 6.5 Medium2025-03-15
CVE-2025-2267 WP01 – Speed, Security, SEO consultant <= 2.6.2 - Authenticated (Subscriber+) Arbitrary File Download — WP01 – Speed, Security, SEO consultant 6.5 Medium2025-03-15
CVE-2025-1657 Directory Listings WordPress plugin – uListing <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Update and PHP Object Injection — Directory Listings WordPress plugin – uListing 8.8 High2025-03-15
CVE-2024-12810 JobCareer | Job Board Responsive WordPress Theme <= 7.1 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrative Actions — JobCareer | Job Board Responsive WordPress Theme 8.8 High2025-03-14
CVE-2025-1507 ShareThis Dashboard for Google Analytics <= 3.2.1 - Missing Authorization to Unauthenticated Feature Deactivation — ShareThis Dashboard for Google Analytics 5.3 Medium2025-03-14
CVE-2025-2103 SoundRise Music <= 1.7 - Authenticated (Subscriber+) Arbitrary Options Update — SoundRise Music 8.8 High2025-03-14
CVE-2025-2289 Zegen - Church WordPress Theme <= 1.1.9 - Missing Authorization to Authenticated (Subscriber+) Theme Options Updates — Zegen - Church WordPress Theme 4.3 Medium2025-03-14
CVE-2025-0952 Eco Nature - Environment & Ecology WordPress Theme <= 2.0.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update — Eco Nature - Environment & Ecology WordPress Theme 8.1 High2025-03-14
CVE-2025-0955 VidoRev Extensions <= 2.9.9.9.9.9.5 - Missing Authorization to Unauthenticated Youtube Video Import — VidoRev Extensions 5.3 Medium2025-03-14
CVE-2025-1528 Search and filter pro <= 2.5.19 - Missing Authorization to Authenticated (Subscriber+) Post Meta Exposure — Search & Filter Pro 4.3 Medium2025-03-14

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.