Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5527

5527 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-28193 JetBrains YouTrack 安全漏洞 — YouTrack 8.8 High2026-02-25
CVE-2026-26104 Udisks: missing authorization check allows unprivileged users to back up luks headers via udisks d-bus api — Red Hat Enterprise Linux 10 5.5 Medium2026-02-25
CVE-2026-26103 Udisks: missing authorization check allows unprivileged users to restore luks headers via udisks d-bus api — Red Hat Enterprise Linux 10 7.1 High2026-02-25
CVE-2026-2301 Post Duplicator <= 3.0.8 - Missing Authorization to Authenticated (Contributor+) Protected Post Meta Insertion via 'customMetaData' Parameter — Post Duplicator 4.3 Medium2026-02-25
CVE-2026-1916 WPGSI: Spreadsheet Integration <= 3.8.3 - Missing Authorization to Unauthenticated Arbitrary Post Creation and Deletion via Forged Base64 Token — WPGSI: Spreadsheet Integration 7.5 High2026-02-25
CVE-2026-27608 Parse Dashboard Missing Authorization on Agent Endpoint — parse-dashboard 8.8AIHighAI2026-02-25
CVE-2026-25131 OpenEMR has Broken Access Control in Procedures Configuration — openemr 8.8 High2026-02-25
CVE-2026-25124 OpenEMR has Broken Access Control in Report/Clients/Message List CSV Export — openemr 6.5 Medium2026-02-25
CVE-2026-22765 Dell Wyse Management Suite WMS 安全漏洞 — Wyse Management Suite 8.8 High2026-02-24
CVE-2026-27468 Mastodon may allow unconfirmed FASP to make subscriptions — mastodon 6.7 -2026-02-24
CVE-2026-1787 LearnPress Export Import <= 4.1.0 - Missing Authentication to Unauthenticated Migrated Course Deletion — LearnPress – Backup & Migration Tool 4.8 Medium2026-02-21
CVE-2025-14339 weMail <= 2.0.7 - Missing Authorization to Unauthenticated Form Deletion — weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce 6.5 Medium2026-02-21
CVE-2026-27484 OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven flows — openclaw 6.5 -2026-02-21
CVE-2026-27471 ERP: Document access through endpoints due to missing validation — erpnext 4.3AIMediumAI2026-02-21
CVE-2026-2039 GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability — Archiver 9.8AICriticalAI2026-02-20
CVE-2026-2038 GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability — Archiver 9.8AICriticalAI2026-02-20
CVE-2026-27111 Kargo has Missing Authorization Vulnerabilities in Approval & Promotion REST API Endpoints — kargo 8.1AIHighAI2026-02-20
CVE-2026-24944 WordPress Subscribe2 plugin <= 10.44 - Broken Access Control vulnerability — Subscribe2 6.5 Medium2026-02-20
CVE-2026-24946 WordPress Print Invoice & Delivery Notes for WooCommerce plugin <= 5.8.0 - Broken Access Control vulnerability — Print Invoice & Delivery Notes for WooCommerce 6.5 Medium2026-02-20
CVE-2026-24941 WordPress WP Job Portal plugin <= 2.4.4 - Broken Access Control vulnerability — WP Job Portal 7.5 High2026-02-20
CVE-2026-22351 WordPress WP FullCalendar plugin <= 1.6 - Broken Access Control vulnerability — WP FullCalendar 7.5 High2026-02-20
CVE-2026-22350 WordPress PDF for Elementor Forms + Drag And Drop Template Builder plugin <= 6.3.1 - Broken Access Control vulnerability — PDF for Elementor Forms + Drag And Drop Template Builder 6.5 Medium2026-02-20
CVE-2025-69393 WordPress Exzo theme <= 1.2.4 - Broken Access Control vulnerability — Exzo 7.5 High2026-02-20
CVE-2025-69388 WordPress Cliengo – Chatbot plugin <= 3.0.4 - Broken Access Control vulnerability — Cliengo – Chatbot 6.5 Medium2026-02-20
CVE-2025-69385 WordPress Cartify - WooCommerce Gutenberg WordPress Theme theme <= 1.3 - Arbitrary Content Deletion vulnerability — Cartify - WooCommerce Gutenberg WordPress Theme 6.5 Medium2026-02-20
CVE-2025-69381 WordPress WooCommerce Bulk Product Editor plugin <= 3.0 - Broken Access Control vulnerability — WooCommerce Bulk Product Editor 7.1 High2026-02-20
CVE-2025-69303 WordPress ModelTheme Framework plugin < 2.0.0 - Broken Access Control vulnerability — ModelTheme Framework 7.5 High2026-02-20
CVE-2025-69297 WordPress Aardvark Plugin plugin <= 2.19 - Broken Access Control vulnerability — Aardvark Plugin 7.5 High2026-02-20
CVE-2025-69298 WordPress Gauge theme <= 6.56.4 - Broken Access Control vulnerability — Gauge 7.5 High2026-02-20
CVE-2025-69063 WordPress New User Approve plugin <= 3.2.0 - Broken Access Control vulnerability — New User Approve 8.6 High2026-02-20

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5527 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.