Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5524

5524 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-3098 Smart Slider 3 <= 3.5.1.33 - Authenticated (Subscriber+) Arbitrary File Read via actionExportAll — Smart Slider 3 6.5 Medium2026-03-27
CVE-2026-29070 Open WebUI has unauthorized deletion of knowledge files — open-webui 5.4 Medium2026-03-26
CVE-2026-33638 Ech0 authenticated user-list exposed data via public `/api/allusers` endpoint — Ech0 5.3 Medium2026-03-26
CVE-2026-33632 ClearanceKit: opfilter policy bypass via exchangedata and clone operations — clearancekit 5.5 -2026-03-26
CVE-2026-33631 ClearanceKit: opfilter policy bypass via non-open file operations — clearancekit 8.7 High2026-03-26
CVE-2026-33495 Ory Oathkeeper has an authentication bypass by usage of untrusted header — oathkeeper 6.5 Medium2026-03-26
CVE-2026-33470 Frigate has cross-camera snapshot disclosure via unrestricted timeline IDs and missing authorization in /api/events/{event_id}/snapshot-clean.webp — frigate 6.5 Medium2026-03-26
CVE-2026-33413 etcd: Authorization bypasses in multiple APIs — etcd 8.6 -2026-03-26
CVE-2026-4281 FormLift for Infusionsoft Web Forms <= 7.5.21 - Missing Authorization to Unauthenticated Infusionsoft Connection Hijack via OAuth Connection Flow — FormLift for Infusionsoft Web Forms 5.3 Medium2026-03-26
CVE-2026-4331 Blog2Social: Social Media Auto Post & Scheduler <= 8.8.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Deletion via 'b2s_reset_social_meta_tags' AJAX Action — Blog2Social: Social Media Auto Post & Scheduler 4.3 Medium2026-03-26
CVE-2026-4484 Masteriyo LMS <= 2.1.6 - Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator — Masteriyo LMS – Online Course Builder for eLearning, LMS & Education 8.8 High2026-03-26
CVE-2026-34053 OpenEMR Missing Authorization in Procedure Order AJAX Deletion Handler — openemr 7.1 High2026-03-25
CVE-2026-33918 OpenEMR Missing Authorization on Claim File Download Endpoint — openemr 7.6 High2026-03-25
CVE-2026-33915 OpenEMR Missing ACL Checks on Insurance Company API Routes — openemr 5.4 Medium2026-03-25
CVE-2025-14595 Missing Authorization in GitLab — GitLab 4.3 Medium2026-03-25
CVE-2026-32546 WordPress Restrict Content plugin <= 3.2.22 - Broken Access Control vulnerability — Restrict Content 8.1 -2026-03-25
CVE-2026-32562 WordPress PPWP plugin <= 1.9.15 - Broken Access Control vulnerability — PPWP 8.2 -2026-03-25
CVE-2026-32541 WordPress Premmerce Redirect Manager plugin <= 1.0.12 - Broken Access Control vulnerability — Premmerce Redirect Manager 8.2 -2026-03-25
CVE-2026-32527 WordPress WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin <= 1.1.5 - Broken Access Control vulnerability — WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms 7.1 -2026-03-25
CVE-2026-32514 WordPress Petitioner plugin <= 0.7.3 - Broken Access Control vulnerability — Petitioner 9.1 -2026-03-25
CVE-2026-32515 WordPress Miraculous theme < 2.1.2 - Broken Access Control vulnerability — Miraculous 8.2 -2026-03-25
CVE-2026-32501 WordPress WP Configurator Pro plugin <= 3.7.9 - Broken Access Control vulnerability — WP Configurator Pro 9.1 -2026-03-25
CVE-2026-32498 WordPress RegistrationMagic plugin <= 6.0.7.6 - Broken Access Control vulnerability — RegistrationMagic 8.1 -2026-03-25
CVE-2026-32495 WordPress WP Terms Popup plugin <= 2.10.0 - Broken Access Control vulnerability — WP Terms Popup 8.2 -2026-03-25
CVE-2026-32489 WordPress B Blocks plugin < 2.0.30 - Broken Access Control vulnerability — B Blocks 8.1 -2026-03-25
CVE-2026-32483 WordPress Contact Form Email plugin <= 1.3.63 - Broken Access Control vulnerability — Contact Form Email 8.2 -2026-03-25
CVE-2026-32485 WordPress WP User Frontend plugin <= 4.2.8 - Broken Access Control vulnerability — WP User Frontend 8.1 -2026-03-25
CVE-2026-32441 WordPress Comments Import & Export plugin <= 2.4.9 - Broken Access Control vulnerability — Comments Import & Export 8.2 -2026-03-25
CVE-2026-31921 WordPress Product Rearrange for WooCommerce plugin <= 1.2.2 - Broken Access Control vulnerability — Product Rearrange for WooCommerce 9.1 -2026-03-25
CVE-2026-27071 WordPress WPCafe plugin <= 3.0.7 - Broken Access Control vulnerability — WPCafe 9.1 -2026-03-25

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5524 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.