Vulnerabilities (CVE)

Filtered by CWE-862
Total 8714 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-65435 2026-07-27 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
CVE-2026-65433 2026-07-27 N/A 6.5 MEDIUM
Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.
CVE-2026-59529 2026-07-27 N/A 7.5 HIGH
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
CVE-2026-59530 2026-07-27 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
CVE-2026-66442 2026-07-27 N/A 5.4 MEDIUM
Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.
CVE-2026-59557 2026-07-27 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
CVE-2026-59536 2026-07-27 N/A 7.5 HIGH
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
CVE-2026-59560 2026-07-27 N/A 6.5 MEDIUM
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
CVE-2026-65567 2026-07-27 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
CVE-2026-0814 2026-07-25 N/A 4.3 MEDIUM
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in all versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export form submissions to excel file.
CVE-2025-15634 1 Hcltech 21 Bigfix Webui Api, Bigfix Webui Application Administration, Bigfix Webui Cmep and 18 more 2026-07-25 N/A 4.3 MEDIUM
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page.
CVE-2025-15565 2026-07-25 N/A 5.3 MEDIUM
The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the redirect function in all versions up to, and including, 8.3.0. This makes it possible for unauthenticated attackers to mark pending WooCommerce orders as paid/completed.
CVE-2026-3208 2026-07-25 N/A 5.3 MEDIUM
The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooCommerce API endpoint in all versions up to, and including, 8.7.11. This makes it possible for unauthenticated attackers to retrieve PIX payment QR code images for arbitrary orders. PIX QR codes contain sensitive merchant information including PIX keys (which may be CPF/CNPJ personal identifiers), transaction amounts, merchant name and city, and MercadoPago transaction references.
CVE-2025-9484 1 Gitlab 1 Gitlab 2026-07-25 N/A 4.3 MEDIUM
GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user to have access to other users' email addresses via certain GraphQL queries.
CVE-2021-47932 2026-07-25 N/A 9.8 CRITICAL
WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler. Attackers can send POST requests to the tcp_register_and_login_ajax action with tcp_role set to administrator to gain full administrative access without authentication.
CVE-2026-58275 2026-07-25 N/A 10.0 CRITICAL
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-2263 2026-07-24 N/A 5.3 MEDIUM
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hustle_module_converted' AJAX action in all versions up to, and including, 7.8.10.2. This makes it possible for unauthenticated attackers to forge conversion tracking events for any Hustle module, including draft modules that are never displayed to users, thereby manipulating marketing analytics and conversion statistics.
CVE-2026-33420 1 Dani-garcia 1 Vaultwarden 2026-07-24 N/A 5.3 MEDIUM
Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing the has_full_access() authorization check that exists on the sibling get_org_collections endpoint. This allows any Manager-role user with accessAll=False and no collection assignments to retrieve the names, UUIDs, user-to-collection mappings, and group-to-collection mappings for all collections in the organization. This issue has been fixed in version 1.35.5.
CVE-2026-33229 1 Xwiki 1 Xwiki 2026-07-24 N/A 9.8 CRITICAL
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the Velocity scripting API and execute, e.g., arbitrary Python scripts, allowing full access to the XWiki instance and thereby compromising the confidentiality, integrity and availability of the whole instance. Note that script right already constitutes a high level of access that we don't recommend giving to untrusted users. This vulnerability is fixed in 17.4.8 and 17.10.1.
CVE-2026-11354 2026-07-24 N/A 5.3 MEDIUM
The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect the private_id-bearing record-access link to an attacker-controlled email address, granting full read and edit access to the victim's stored personally identifiable information including names, email addresses, phone numbers, and any other fields collected in the participant database. An attacker can harvest a valid nonce with a plain unauthenticated GET request to any page rendering the public signup or record form, then POST action=update with an arbitrary id value to overwrite any record; chaining a subsequent action=retrieve then delivers the private-access link to the attacker-controlled mailbox.