Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5524

5524 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-34184 Missing Authorization in Hydrosystem Control System — Control System 9.8AICriticalAI2026-04-09
CVE-2026-1830 Quick Playground <= 1.3.1 - Missing Authorization to Unauthenticated Arbitrary File Upload — Quick Playground 9.8 Critical2026-04-09
CVE-2026-4124 Ziggeo <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'ziggeo_ajax' AJAX Action — Ziggeo 5.4 Medium2026-04-09
CVE-2026-4326 Vertex Addons for Elementor <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation and Activation via 'afeb_activate_required_plugins' — Vertex Addons for Elementor 8.8 High2026-04-09
CVE-2025-9484 Missing Authorization in GitLab — GitLab 4.3 Medium2026-04-08
CVE-2026-4916 Missing Authorization in GitLab — GitLab 2.7 Low2026-04-08
CVE-2026-39429 kcp's cache server is accessible without authentication or authorization checks — kcp 8.2 High2026-04-08
CVE-2026-34837 Zammad is miissing authorization in AI assistance controller for context data used in text tools — zammad 7.1AIHighAI2026-04-08
CVE-2026-34782 Zammad has improper access control in AI assistance controller for text tools — zammad 8.8AIHighAI2026-04-08
CVE-2026-34722 Zammad is missing authorization in ticket create endpoint — zammad 4.3AIMediumAI2026-04-08
CVE-2026-0814 Advanced CF7 DB <= 2.0.9 - Missing Authorization to Authenticated (Subscriber+) Form Submissions Excel Export — Advanced Contact form 7 DB 4.3 Medium2026-04-08
CVE-2026-33229 XWiki Platform affected by remote code execution with script right through unprotected Velocity scripting API — xwiki-platform 9.9AICriticalAI2026-04-08
CVE-2026-39715 WordPress AnyTrack Affiliate Link Manager plugin <= 1.5.5 - Broken Access Control vulnerability — AnyTrack Affiliate Link Manager 8.1AIHighAI2026-04-08
CVE-2026-39716 WordPress Flipmart theme <= 2.8 - Broken Access Control vulnerability — Flipmart 9.1AICriticalAI2026-04-08
CVE-2026-39713 WordPress Mailercloud – Integrate webforms and synchronize website contacts plugin <= 1.0.7 - Broken Access Control vulnerability — Mailercloud &#8211; Integrate webforms and synchronize website contacts 8.2AIHighAI2026-04-08
CVE-2026-39714 WordPress G5Plus April theme <= 6.8 - Broken Access Control vulnerability — G5Plus April 8.1AIHighAI2026-04-08
CVE-2026-39706 WordPress Make My Trivia plugin <= 1.1.0 - Broken Access Control vulnerability — Make My Trivia 8.2AIHighAI2026-04-08
CVE-2026-39705 WordPress MIPL WC Multisite Sync plugin <= 1.4.4 - Broken Access Control vulnerability — MIPL WC Multisite Sync 9.1AICriticalAI2026-04-08
CVE-2026-39707 WordPress Accept PayPal Payments using Contact Form 7 plugin <= 4.0.4 - Broken Access Control vulnerability — Accept PayPal Payments using Contact Form 7 9.1AICriticalAI2026-04-08
CVE-2026-39701 WordPress ShopWP plugin <= 5.2.4 - Broken Access Control vulnerability — ShopWP 8.1AIHighAI2026-04-08
CVE-2026-39704 WordPress Precious Metals Automated Product Pricing – Pro plugin <= 4.0.5 - Broken Access Control vulnerability — Precious Metals Automated Product Pricing &#8211; Pro 8.2AIHighAI2026-04-08
CVE-2026-39700 WordPress WowOptin plugin <= 1.4.32 - Broken Access Control vulnerability — WowOptin 9.1AICriticalAI2026-04-08
CVE-2026-39699 WordPress AI Workflow Automation plugin <= 1.4.2 - Broken Access Control vulnerability — AI Workflow Automation 9.1AICriticalAI2026-04-08
CVE-2026-39697 WordPress MAIO – The new AI GEO / SEO tool plugin <= 6.2.8 - Broken Access Control vulnerability — MAIO &#8211; The new AI GEO / SEO tool 7.1AIHighAI2026-04-08
CVE-2026-39698 WordPress The Publisher Desk ads.txt plugin <= 1.5.0 - Broken Access Control vulnerability — The Publisher Desk ads.txt 8.1AIHighAI2026-04-08
CVE-2026-39694 WordPress Simply Schedule Appointments plugin <= 1.6.10.2 - Broken Access Control vulnerability — Simply Schedule Appointments 8.1AIHighAI2026-04-08
CVE-2026-39690 WordPress Author Avatars List/Block plugin <= 2.1.25 - Broken Access Control vulnerability — Author Avatars List/Block 8.1AIHighAI2026-04-08
CVE-2026-39691 WordPress Cryptocurrency Donation Box – Bitcoin & Crypto Donations plugin <= 2.2.13 - Broken Access Control vulnerability — Cryptocurrency Donation Box – Bitcoin & Crypto Donations 9.1AICriticalAI2026-04-08
CVE-2026-39689 WordPress eShipper Commerce plugin <= 2.16.12 - Broken Access Control vulnerability — eShipper Commerce 8.2AIHighAI2026-04-08
CVE-2026-39688 WordPress WP Frontend Profile plugin <= 1.3.9 - Broken Access Control vulnerability — WP Frontend Profile 9.1AICriticalAI2026-04-08

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5524 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.