Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-5417 Funnelforms Free <= 3.4 - Missing Authorization to Category Update — Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 4.3 Medium2023-11-22
CVE-2023-47757 WordPress AWeber Plugin <= 7.3.9 is vulnerable to Broken Access Control — AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth 4.3 Medium2023-11-17
CVE-2023-39544 NEC Expresscluster X 安全漏洞 — CLUSTERPRO X(EXPRESSCLUSTER X) 8.8 -2023-11-17
CVE-2023-47112 Authenticated users can view job names and groups they do not have authorization to view in Rundeck — rundeck 4.3 Medium2023-11-16
CVE-2023-48222 Authenticated users can view or delete jobs they do not have authorization for in Rundeck — rundeck 8.1 High2023-11-16
CVE-2023-6020 Ray Static File Local File Include — ray-project/ray 7.5 -2023-11-16
CVE-2023-6038 Local File Inclusion in h2oai/h2o-3 — h2oai/h2o-3 7.5 -2023-11-16
CVE-2023-4723 Elementor Addon Elements <= 1.12.7 - Missing Authorization to Sensitive Information Exposure — Addon Elements for Elementor (formerly Elementor Addon Elements) 5.3 Medium2023-11-15
CVE-2023-5506 ImageMapper <= 1.2.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Page/Post Deletion via imgmap_delete_area_ajax — ImageMapper 5.4 Medium2023-11-07
CVE-2023-4700 Missing Authorization in GitLab — GitLab 3.5 Low2023-11-06
CVE-2023-4198 Dolibarr ERP CRM (<= 17.0.3) Improper Access Control — Dolibarr ERP CRM 6.5 Medium2023-11-01
CVE-2022-3007 Unauthorized Access Vulnerability in Syska SW100 Smartwatch — Syska SW100 Smartwatch 8.1 High2023-10-31
CVE-2023-5862 Missing Authorization in hamza417/inure — hamza417/inure 8.8 -2023-10-31
CVE-2023-5251 Grid Plus <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Grid Layout Add/Update/Delete — Grid Plus – Unlimited grid layout 5.4 Medium2023-10-30
CVE-2023-5425 Post Meta Data Manager <=1.2.0 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation — Post Meta Data Manager 8.8 High2023-10-28
CVE-2023-5426 Post Meta Data Manager <=1.2.0 - Missing Authorization to User, Term, and Post Meta Deletion — Post Meta Data Manager 7.5 High2023-10-28
CVE-2023-37910 org.xwiki.platform:xwiki-platform-attachment-api vulnerable to Missing Authorization on Attachment Move — xwiki-platform 8.1 High2023-10-25
CVE-2023-43488 Bosch ctrlX HMI Web Panel WR21 安全漏洞 — ctrlX HMI Web Panel - WR21 (WR2107) 7.9 High2023-10-25
CVE-2023-5311 WP EXtra <= 6.2 - Missing Authorization to .htaccess File Modification — WP EXtra – One Click Optimize 8.8 High2023-10-25
CVE-2023-4606 Lenovo XClarity Controller 安全漏洞 — Lenovo XClarity Controller (XCC) 8.1 High2023-10-24
CVE-2023-5132 Soisy Pagamento Rateale <= 6.0.1 - Missing Authorization to Sensitive Information Exposure — Soisy Pagamento Rateale 7.5 High2023-10-21
CVE-2022-3622 Blog2Social <= 6.9.11 - Missing Authorization to Authenticated (Subscriber+) Settings Update — Blog2Social: Social Media Auto Post & Scheduler 4.1 Medium2023-10-20
CVE-2023-4668 Ad Inserter <= 2.7.30 - Unauthenticated Sensitive Information Exposure via ai-debug-processing-fe — Ad Inserter – Ad Manager & AdSense Ads 5.3 Medium2023-10-20
CVE-2023-4941 BEAR <= 1.1.3.3 - Missing Authorization to Product Manipulation — BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net 4.3 Medium2023-10-20
CVE-2023-5533 AI ChatBot <= 4.8.9 and 4.9.2 - Missing Authorization on AJAX actions — WPBot – AI ChatBot for Live Support, Lead Generation, AI Services 5.3 Medium2023-10-20
CVE-2022-4943 miniOrange's Google Authenticator <= 5.6.5 - Missing Authorization to Plugin Settings Change — miniOrange 2FA – Two-Factor Authentication for WordPress (SMS, Email & Google Authenticator) 7.5 High2023-10-20
CVE-2023-4943 BEAR <= 1.1.3.3 - Missing Authorization to Product Manipulation — BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net 4.3 Medium2023-10-20
CVE-2023-4947 WooCommerce EAN Payment Gateway < 6.1.0 - Missing Authorization to Authenticated (Contributor+) EAN Update — WooCommerce EAN Payment Gateway 4.3 Medium2023-10-20
CVE-2020-36698 Security & Malware scan by CleanTalk <= 2.50 - Missing Authorization — Login Security, FireWall, Malware removal by CleanTalk 8.8 High2023-10-20
CVE-2023-4645 Ad Inserter <= 2.7.30 - Unauthenticated Sensitive Information Exposure via ai_ajax — Ad Inserter – Ad Manager & AdSense Ads 5.3 Medium2023-10-19

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.