CWE-862 授权机制缺失 类弱点 7360 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-862 属于缺失授权漏洞,指产品在用户访问资源或执行操作时未进行权限校验。攻击者通常通过直接修改请求参数或构造恶意 URL,绕过前端限制以访问未授权数据或执行敏感操作。开发者应避免仅依赖前端验证,需在服务端对每个请求实施严格的身份认证与权限检查,确保用户仅能访问其被授权的资源,从而从根本上消除越权风险。
function runEmployeeQuery($dbName, $name){ mysql_select_db($dbName,$globalDbHandle) or die("Could not open Database".$dbName); //Use a prepared statement to avoid CWE-89 $preparedStatement = $globalDbHandle->prepare('SELECT * FROM employees WHERE name = :name'); $preparedStatement->execute(array(':name' => $name)); return $preparedStatement->fetchAll(); } /.../ $employeeRecord = runEmployeeQuery('EmployeeDB',$_GET['EmployeeName']);
sub DisplayPrivateMessage { my($id) = @_; my $Message = LookupMessageObject($id); print "From: " . encodeHTML($Message->{from}) . "<br>\n"; print "Subject: " . encodeHTML($Message->{subject}) . "\n"; print "<hr>\n"; print "Body: " . encodeHTML($Message->{body}) . "\n"; } my $q = new CGI; # For purposes of this example, assume that CWE-309 and # CWE-523 do not apply. if (! AuthenticateUser($q->param('username'), $q->param('password'))) { ExitError("invalid username or password"); } my $id = $q->param('id'); DisplayPrivateMessage($id);
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-12937 | WordPress plugin ACF Flexible Layouts Manager 安全漏洞 — ACF Flexible Layouts Manager | 6.5 | Medium | 2025-11-18 |
| CVE-2025-11620 | WordPress plugin Multiple Roles per User 安全漏洞 — Multiple Roles per User | 7.2 | High | 2025-11-18 |
| CVE-2025-6171 | GitLab 安全漏洞 — GitLab | 5.3 | Medium | 2025-11-15 |
| CVE-2025-12849 | WordPress plugin Contest Gallery 安全漏洞 — Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | 5.3 | Medium | 2025-11-15 |
| CVE-2025-12847 | WordPress plugin All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic 安全漏洞 — All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic | 4.3 | Medium | 2025-11-15 |
| CVE-2025-12817 | PostgreSQL 安全漏洞 — PostgreSQL | 3.1 | Low | 2025-11-13 |
| CVE-2025-12377 | WordPress plugin Gallery Plugin for WordPress – Envira Photo Gallery 安全漏洞 — Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More | 4.3 | Medium | 2025-11-13 |
| CVE-2025-64384 | WordPress plugin JetFormBuilder 安全漏洞 — JetFormBuilder | 5.3 | Medium | 2025-11-13 |
| CVE-2025-64382 | WordPress plugin Order Export & Order Import for WooCommerce 安全漏洞 — Order Export & Order Import for WooCommerce | 4.3 | Medium | 2025-11-13 |
| CVE-2025-64370 | WordPress plugin YOP Poll 安全漏洞 — YOP Poll | 5.3 | Medium | 2025-11-13 |
| CVE-2025-64379 | WordPress plugin Booster for WooCommerce 安全漏洞 — Booster for WooCommerce | 4.3 | Medium | 2025-11-13 |
| CVE-2025-64369 | WordPress plugin Contact Form Email 安全漏洞 — Contact Form Email | 6.5 | Medium | 2025-11-13 |
| CVE-2025-64277 | WordPress plugin ChatBot 安全漏洞 — ChatBot | 5.3 | Medium | 2025-11-13 |
| CVE-2025-64276 | WordPress plugin Survey Maker 安全漏洞 — Survey Maker | 6.5 | Medium | 2025-11-13 |
| CVE-2025-64274 | WordPress plugin WPKoi Templates for Elementor 安全漏洞 — WPKoi Templates for Elementor | 4.3 | Medium | 2025-11-13 |
| CVE-2025-64269 | WordPress plugin WooCommerce PDF Invoice Builder 安全漏洞 — WooCommerce PDF Invoice Builder | 4.3 | Medium | 2025-11-13 |
| CVE-2025-64265 | WordPress plugin Frontend File Manager 安全漏洞 — Frontend File Manager | 4.3 | Medium | 2025-11-13 |
| CVE-2025-64263 | WordPress plugin WP Content Pilot 安全漏洞 — WP Content Pilot | 5.4 | Medium | 2025-11-13 |
| CVE-2025-64259 | WordPress plugin Theater for WordPress 安全漏洞 — Theater for WordPress | 5.3 | Medium | 2025-11-13 |
| CVE-2025-64261 | WordPress plugin Appointment Booking Calendar 安全漏洞 — Appointment Booking Calendar | 5.4 | Medium | 2025-11-13 |
| CVE-2025-12015 | WordPress plugin quicq 安全漏洞 — Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeed | 4.3 | Medium | 2025-11-13 |
| CVE-2025-12891 | WordPress plugin Survey Maker 安全漏洞 — Survey Maker | 5.3 | Medium | 2025-11-13 |
| CVE-2025-12979 | WordPress plugin Welcart e-Commerce 安全漏洞 — Welcart e-Commerce | 5.3 | Medium | 2025-11-13 |
| CVE-2025-12892 | WordPress plugin Survey Maker 安全漏洞 — Survey Maker | 5.3 | Medium | 2025-11-13 |
| CVE-2025-13063 | Dee Store 安全漏洞 — Dee Store | 7.3 | High | 2025-11-12 |
| CVE-2025-64407 | Apache OpenOffice 安全漏洞 — Apache OpenOffice | 4.0 | - | 2025-11-12 |
| CVE-2025-64405 | Apache OpenOffice 安全漏洞 — Apache OpenOffice | 6.2 | - | 2025-11-12 |
| CVE-2025-64404 | Apache OpenOffice 安全漏洞 — Apache OpenOffice | 6.8 | - | 2025-11-12 |
| CVE-2025-64403 | Apache OpenOffice 安全漏洞 — Apache OpenOffice | 4.0 | - | 2025-11-12 |
| CVE-2025-64402 | Apache OpenOffice 安全漏洞 — Apache OpenOffice | 6.2 | - | 2025-11-12 |
CWE-862(授权机制缺失) 是常见的弱点类别,本平台收录该类弱点关联的 7360 条 CVE 漏洞。