Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5525

5525 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-32374 WordPress The Minimal theme <= 1.2.9 - Broken Access Control vulnerability — The Minimal 8.2 -2026-03-13
CVE-2026-32370 WordPress Influencer theme <= 1.1.7 - Broken Access Control vulnerability — Influencer 8.1 -2026-03-13
CVE-2026-32362 WordPress WP Sessions Time Monitoring Full Automatic plugin <= 1.1.3 - Broken Access Control vulnerability — WP Sessions Time Monitoring Full Automatic 9.1 -2026-03-13
CVE-2026-32363 WordPress WPLifeCycle plugin <= 3.3.1 - Broken Access Control vulnerability — WPLifeCycle 8.2 -2026-03-13
CVE-2026-32350 WordPress Chocolate House theme <= 1.1.5 - Broken Access Control vulnerability — Chocolate House 9.1 -2026-03-13
CVE-2026-32348 WordPress MAS Videos plugin <= 1.3.2 - Broken Access Control vulnerability — MAS Videos 9.1 -2026-03-13
CVE-2026-32347 WordPress Restaurant and Cafe theme <= 1.2.5 - Broken Access Control vulnerability — Restaurant and Cafe 9.1 -2026-03-13
CVE-2026-32346 WordPress Travel Agency theme <= 1.5.5 - Broken Access Control vulnerability — Travel Agency 9.1 -2026-03-13
CVE-2026-32345 WordPress Perfect Portfolio theme <= 1.2.4 - Broken Access Control vulnerability — Perfect Portfolio 7.1 -2026-03-13
CVE-2026-32339 WordPress Bakes And Cakes theme <= 1.2.9 - Broken Access Control vulnerability — Bakes And Cakes 8.2 -2026-03-13
CVE-2026-32340 WordPress Business One Page theme <= 1.3.2 - Broken Access Control vulnerability — Business One Page 7.1 -2026-03-13
CVE-2026-32337 WordPress Preschool and Kindergarten theme <= 1.2.5 - Broken Access Control vulnerability — Preschool and Kindergarten 8.1 -2026-03-13
CVE-2026-32341 WordPress Benevolent theme <= 1.3.9 - Broken Access Control vulnerability — Benevolent 8.1 -2026-03-13
CVE-2026-32338 WordPress Construction Landing Page theme <= 1.4.1 - Broken Access Control vulnerability — Construction Landing Page 8.2 -2026-03-13
CVE-2026-32336 WordPress Rara Business theme <= 1.3.0 - Broken Access Control vulnerability — Rara Business 8.1 -2026-03-13
CVE-2026-32334 WordPress JobScout theme <= 1.1.7 - Broken Access Control vulnerability — JobScout 8.2 -2026-03-13
CVE-2026-32335 WordPress The Conference theme <= 1.2.5 - Broken Access Control vulnerability — The Conference 7.1 -2026-03-13
CVE-2026-32332 WordPress Easy Form plugin <= 2.7.9 - Broken Access Control vulnerability — Easy Form 9.1 -2026-03-13
CVE-2026-32329 WordPress Advanced Related Posts plugin <= 1.9.1 - Broken Access Control vulnerability — Advanced Related Posts 7.1 -2026-03-13
CVE-2026-32331 WordPress Textmetrics plugin <= 3.6.4 - Broken Access Control vulnerability — Textmetrics 9.1 -2026-03-13
CVE-2026-31916 WordPress Latest Post Shortcode plugin <= 14.2.1 - Broken Access Control vulnerability — Latest Post Shortcode 9.1 -2026-03-13
CVE-2026-31919 WordPress Advanced Coupons for WooCommerce Coupons plugin <= 4.7.1 - Broken Access Control vulnerability — Advanced Coupons for WooCommerce Coupons 9.1 -2026-03-13
CVE-2026-31915 WordPress Flatsome theme <= 3.19.6 - Broken Access Control vulnerability — Flatsome 9.1 -2026-03-13
CVE-2026-4063 Social Icons Widget & Block <= 4.5.8 - Missing Authorization to Authenticated (Subscriber+) Sharing Configuration Creation — Social Icons Widget & Block – Social Media Icons & Share Buttons 4.3 Medium2026-03-13
CVE-2026-2890 Formidable Forms <= 6.28 - Missing Authorization to Unauthenticated Payment Integrity Bypass via PaymentIntent Reuse — Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder 7.5 High2026-03-13
CVE-2026-3045 Appointment Booking Calendar <= 1.6.9.29 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint — Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin 7.5 High2026-03-13
CVE-2026-22182 wpDiscuz before 7.6.47 - Unauthenticated Email Notification Flood via wpdCheckNotificationType — wpDiscuz 7.5 High2026-03-13
CVE-2026-32230 Uptime Kuma is Missing Authorization Checks on Ping Badge Endpoint, Leaks Ping times of monitors without needing to be on a status page — uptime-kuma 5.3 Medium2026-03-12
CVE-2026-28254 Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge — Tracer SC 7.5AIHighAI2026-03-12
CVE-2026-3977 projectsend AJAX Endpoints authorization — projectsend 6.3 Medium2026-03-12

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5525 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.