Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-27461 CVE-2025-27461 — Endress+Hauser MEAC300-FNADE4 7.6 High2025-07-03
CVE-2025-53108 HomeBox Missing User Authorization — homebox 7.1AIHighAI2025-07-02
CVE-2025-39362 WordPress Mollie Payments for WooCommerce plugin <= 8.0.2 - Insecure Direct Object References (IDOR) vulnerability — Mollie Payments for WooCommerce 6.5 Medium2025-07-02
CVE-2025-5692 Lead Form Data Collection to CRM <= 3.1 - Missing Authorization to Authenticated (Subscriber+) Many Actions — Lead Form Data Collection to CRM 6.3 Medium2025-07-02
CVE-2025-46259 WordPress The Plus Addons for Elementor - Pro Plugin < 6.3.7 - Broken Access Control vulnerability — The Plus Addons for Elementor Pro 5.4 Medium2025-07-01
CVE-2025-5304 PT Project Notebooks 1.0.0 - 1.1.3 - Missing Authorization to Unauthenticated Privilege Escalation via wpnb_pto_new_users_add Function — PT Project Notebooks – Take Meeting minutes, create budgets, track task management, and more 9.8 Critical2025-06-28
CVE-2025-53323 WordPress Pre-Publish Post Checklist plugin <= 3.1 - Broken Access Control Vulnerability — Pre-Publish Post Checklist 4.3 Medium2025-06-27
CVE-2025-53318 WordPress WP DB Booster plugin <= 1.0.1 - Broken Access Control Vulnerability — WP DB Booster 5.4 Medium2025-06-27
CVE-2025-53304 WordPress Contact Form – 7 : Hide Success Message plugin <= 1.1.4 - Broken Access Control Vulnerability — Contact Form – 7 : Hide Success Message 5.3 Medium2025-06-27
CVE-2025-53295 WordPress iCount Payment Gateway plugin <= 2.0.7 - Broken Access Control Vulnerability — iCount Payment Gateway 5.3 Medium2025-06-27
CVE-2025-53293 WordPress Dashboard Widget Sidebar plugin <= 1.2.3 - Broken Access Control Vulnerability — Dashboard Widget Sidebar 4.3 Medium2025-06-27
CVE-2025-53288 WordPress PlatiOnline Payments plugin <= 7.0.0 - Broken Access Control vulnerability — PlatiOnline Payments 4.3 Medium2025-06-27
CVE-2025-53284 WordPress CMS Blocks plugin <= 1.1 - Broken Access Control Vulnerability — CMS Blocks 6.5 Medium2025-06-27
CVE-2025-53266 WordPress Cron Logger plugin <= 1.3.0 - Broken Access Control Vulnerability — Cron Logger 4.3 Medium2025-06-27
CVE-2025-53255 WordPress HurryTimer plugin <= 2.13.1 - Broken Access Control Vulnerability — HurryTimer 5.3 Medium2025-06-27
CVE-2025-53200 WordPress ChatBot plugin <= 6.7.3 - Broken Access Control Vulnerability — ChatBot 4.3 Medium2025-06-27
CVE-2025-52817 WordPress Abandoned Contact Form 7 plugin <= 2.2 - Broken Access Control vulnerability — Abandoned Contact Form 7 8.2 High2025-06-27
CVE-2025-52818 WordPress Trusty Whistleblowing plugin <= 2.0.1 - Broken Access Control vulnerability — Trusty Whistleblowing 8.2 High2025-06-27
CVE-2025-52824 WordPress Mobile DJ Manager plugin <= 1.7.8.3 - Privilege Escalation vulnerability — Mobile DJ Manager 8.8 High2025-06-27
CVE-2025-5315 Missing Authorization in GitLab — GitLab 4.3 Medium2025-06-26
CVE-2025-5846 Missing Authorization in GitLab — GitLab 2.7 Low2025-06-26
CVE-2025-5813 Amazon Products to WooCommerce <= 1.2.7 - Missing Authorization to Unauthenticated Arbitrary Product Creation — Amazon Products to WooCommerce 5.3 Medium2025-06-26
CVE-2025-5812 VG WORT METIS <= 2.0.0 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update — VG WORT METIS 4.3 Medium2025-06-26
CVE-2025-3863 Post Carousel Slider for Elementor <= 1.6.0 - Authenticated (Subscriber+) Missing Authorization via process_wbelps_promo_form Function — Post Carousel Slider for Elementor 4.3 Medium2025-06-26
CVE-2025-52878 JetBrains TeamCity 安全漏洞 — TeamCity 4.3 Medium2025-06-23
CVE-2023-5600 Missing Authorization in GitLab — GitLab 3.1 Low2025-06-20
CVE-2025-5121 Missing Authorization in GitLab — GitLab 8.5 High2025-06-20
CVE-2025-49970 WordPress Hello FSE Blog theme <= 1.0.6 - Broken Access Control Vulnerability — Hello FSE Blog 4.3 Medium2025-06-20
CVE-2025-49969 WordPress Zara 4 Image Compression plugin <= 1.2.17.2 - Broken Access Control Vulnerability — Zara 4 Image Compression 4.3 Medium2025-06-20
CVE-2025-49971 WordPress eDS Responsive Menu plugin <= 1.2 - Broken Access Control Vulnerability — eDS Responsive Menu 4.3 Medium2025-06-20

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.