Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

8,769 CVEs tagged with CWE-862439 Critical, 1,977 High, 6,059 Medium, 293 Low, 1 Unrated.

CVE-2026-66751

Published Jul 28, 2026

Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server by sending a DELETE request to…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-66750

Published Jul 28, 2026

Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to download file attachments from private and password-protected…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-16774

Published Jul 28, 2026

The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. This is due to the wpcs_sen…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-15411

Published Jul 28, 2026

The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to authorization bypass in all vers…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-15025

Published Jul 28, 2026

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3…

CVSS 7.5 · High
evidence mentions
14
Buzz score
33.6

CVE-2026-13110

Published Jul 28, 2026

The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a missing capability check on the b…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-14168

Published Jul 28, 2026

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system acce…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16587

Published Jul 28, 2026

The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to t…

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-14924

Published Jul 28, 2026

The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-14821

Published Jul 28, 2026

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-12124

Published Jul 28, 2026

The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-66473

Published Jul 27, 2026

Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65445

Published Jul 27, 2026

Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-64746

Published Jul 27, 2026

An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. An app may be able t…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-43665

Published Jul 27, 2026

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able to determine the legacy…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-65922

Published Jul 27, 2026

An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under sp…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-66477

Published Jul 27, 2026

Unauthenticated Broken Access Control in Gillion <= 4.13 versions.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-66442

Published Jul 27, 2026

Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65568

Published Jul 27, 2026

Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65567

Published Jul 27, 2026

Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65435

Published Jul 27, 2026

Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65433

Published Jul 27, 2026

Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-59560

Published Jul 27, 2026

Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-59557

Published Jul 27, 2026

Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-59536

Published Jul 27, 2026

Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 8,769 CVEsPage 1 of 351