Vulnerabilities (CVE)

Filtered by CWE-862
Total 9924 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-49070 2026-06-17 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.
CVE-2026-49065 2026-06-17 N/A 8.2 HIGH
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.
CVE-2026-49054 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Post Grid: from n/a through 7.9.2.
CVE-2026-49053 2026-06-17 N/A 5.3 MEDIUM
Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.
CVE-2026-49052 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.
CVE-2026-49051 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Meta and Date Remover: from n/a through 2.3.6.
CVE-2026-49047 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DearFlip: from n/a through 2.4.27.
CVE-2026-49045 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Adminimize: from n/a through 1.11.11.
CVE-2026-48973 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SVG Support: from n/a through 2.5.14.
CVE-2026-48971 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in WebToffee Product Import Export for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Product Import Export for WooCommerce: from n/a through 2.5.6.
CVE-2026-48969 2026-06-17 N/A 6.5 MEDIUM
Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions.
CVE-2026-48887 2026-06-17 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.
CVE-2026-48883 2026-06-17 N/A 7.5 HIGH
Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.
CVE-2026-48881 2026-06-17 N/A 9.1 CRITICAL
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.
CVE-2026-48873 2026-06-17 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions.
CVE-2026-48835 2026-06-17 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
CVE-2026-48151 2026-06-17 N/A 7.5 HIGH
Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under builderRoutes, but the generic authorization middleware skips authorization for all paths matching /api/webhooks/schema. As a result, an unauthenticated caller can update the body schema for a known webhook and mutate the corresponding automation trigger output schema. This vulnerability is fixed in 3.39.0.
CVE-2026-48119 2026-06-17 N/A 7.1 HIGH
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.12, authenticated agents can forge service-monitor results for other users' services. This issue has been patched in version 2.0.12.
CVE-2026-47197 2026-06-17 N/A N/A
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can use the bot to moderate users above them in the Discord role hierarchy, as long as the bot itself outranks the target. This bypasses Discord’s normal role hierarchy protections and lets lower-ranked moderators ban, kick, timeout, untimeout, warn, or rename higher-ranked users. This issue has been patched in version 1.1.6.
CVE-2026-47163 2026-06-17 N/A N/A
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.1, any guild member who can invoke slash commands can use /automod add, /automod remove, and /automod list because the command has no Discord default permission requirement and no runtime moderator permission check. An attacker can add a rule matching common text and make the bot delete other users’ messages. This issue has been patched in version 1.0.1.