Vulnerabilities (CVE)

Filtered by CWE-862
Total 9919 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-57645 2026-06-26 N/A 8.1 HIGH
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
CVE-2026-57632 2026-06-26 N/A 5.4 MEDIUM
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.
CVE-2026-57622 2026-06-26 N/A 4.3 MEDIUM
Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.
CVE-2026-57324 2026-06-26 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.
CVE-2026-57323 2026-06-26 N/A 5.8 MEDIUM
Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.
CVE-2026-56063 2026-06-26 N/A 8.3 HIGH
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
CVE-2026-56038 2026-06-26 N/A 8.8 HIGH
Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.
CVE-2026-56025 2026-06-26 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.
CVE-2026-54840 2026-06-26 N/A 7.3 HIGH
Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.
CVE-2026-54832 2026-06-26 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
CVE-2026-52701 2026-06-26 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.
CVE-2025-63078 2026-06-26 N/A 4.3 MEDIUM
Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.
CVE-2025-63041 2026-06-26 N/A 5.4 MEDIUM
Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.
CVE-2026-27608 1 Parseplatform 1 Parse Dashboard 2026-06-26 N/A 8.1 HIGH
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) does not enforce authorization. Authenticated users scoped to specific apps can access any other app's agent endpoint by changing the app ID in the URL. Read-only users are given the full master key instead of the read-only master key and can supply write permissions in the request body to perform write and delete operations. Only dashboards with `agent` configuration enabled are affected. The fix in version 9.0.0-alpha.8 adds per-app authorization checks and restricts read-only users to the `readOnlyMasterKey` with write permissions stripped server-side. As a workaround, remove the `agent` configuration block from your dashboard configuration. Dashboards without an `agent` config are not affected.
CVE-2026-57640 2026-06-26 N/A 4.3 MEDIUM
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.
CVE-2026-57430 2026-06-26 N/A 4.3 MEDIUM
Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.
CVE-2026-54847 2026-06-26 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.
CVE-2026-54846 2026-06-26 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Syncee Premium Dropshipping &amp; Wholesale <= 1.0.27 versions.
CVE-2025-64636 2026-06-26 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.
CVE-2025-63079 2026-06-26 N/A 4.3 MEDIUM
Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.