Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified MEDIUM 5.3
CVE-2025-15510

The NEX-Forms – Ultimate Forms Plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the NF5_Export_…

Mitigation only
Fix from $1,600 2026-01-31
Discourse MEDIUM 6.5
CVE-2026-21865

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can convert some personal…

Fix: 3.5.4 / 2025.11.2+
Fix from $1,600 2026-01-28
Discourse MEDIUM 5.3
CVE-2025-68479

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some subscription endpoints lack pro…

Fix: 3.5.4 / 2025.11.2+
Fix from $1,600 2026-01-28
Unclassified HIGH 7.5
CVE-2026-1280

The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability check on the 'wpfm_send_file_in…

Mitigation only
Fix from $1,950 2026-01-28
Unclassified MEDIUM 5.3
CVE-2025-15511

The Rupantorpay plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_webhook() fun…

Mitigation only
Fix from $1,600 2026-01-28
Unclassified HIGH 8.8
CVE-2025-14386

The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authenticati…

Mitigation only
Fix from $1,950 2026-01-28
Unclassified MEDIUM 5.3
CVE-2026-1054

The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0.7.4. This is due to missing n…

Mitigation only
Fix from $1,600 2026-01-28
Unclassified MEDIUM 5.3
CVE-2026-0825

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to authorization bypass due to missing capability checks…

Mitigation only
Fix from $1,600 2026-01-28
Unclassified HIGH 7.3
CVE-2026-0832

The New User Approve plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on …

Mitigation only
Fix from $1,950 2026-01-28
Unclassified MEDIUM 5.3
CVE-2026-1310

The Simple calendar for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.6. This is du…

Mitigation only
Fix from $1,600 2026-01-28
Studiocms MEDIUM 6.5
CVE-2026-24134

StudioCMS is a server-side-rendered, Astro native, headless content management system. Versions prior to 0.2.0 contain a Broken Object Level Authoriz…

Fix: 0.2.0+
Fix from $1,600 2026-01-28
Unclassified MEDIUM 5.3
CVE-2025-14971

The Link Invoice Payment for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on…

Mitigation only
Fix from $1,600 2026-01-27
Unclassified MEDIUM 5.3
CVE-2026-0593

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on…

Mitigation only
Fix from $1,600 2026-01-24
Unclassified MEDIUM 5.4
CVE-2026-1103

The AIKTP plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the /aiktp/getToken REST API…

Mitigation only
Fix from $1,600 2026-01-24
Unclassified MEDIUM 5.3
CVE-2025-14843

The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in all versions up to, and inclu…

Mitigation only
Fix from $1,600 2026-01-24
Unclassified MEDIUM 5.3
CVE-2025-14609

The Wise Analytics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.9. This is due to missing ca…

Mitigation only
Fix from $1,600 2026-01-24
Unclassified MEDIUM 5.3
CVE-2025-14629

The Alchemist Ajax Upload plugin for WordPress is vulnerable to unauthorized media file deletion due to a missing capability check on the 'delete_fil…

Mitigation only
Fix from $1,600 2026-01-24
Phpmyfaq MEDIUM 6.5
CVE-2026-24421

phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below have flawed authorization logic which exposes the /api/setup/backup endpoin…

Fix: 4.0.17+
Fix from $1,600 2026-01-24
Mytube MEDIUM 6.5
CVE-2026-24139

MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below do not safeguard against authorization bypass, al…

Fix: after 1.7.78
Fix from $1,600 2026-01-24
Gemscms Backend CRITICAL 9.4
CVE-2025-52024

A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthenticated us…

Fix: after 2025-05-28
Fix from $2,300 2026-01-23
Ruoyi HIGH 7.5
CVE-2025-70986

Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access sensitive department data.

No fix yet
Fix from $1,950 2026-01-23
Springblade CRITICAL 9.9
CVE-2025-70983

Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.

Mitigation only
Fix from $2,300 2026-01-23
Ruoyi CRITICAL 9.1
CVE-2025-70985

Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.

No fix yet
Fix from $2,300 2026-01-23
Unclassified MEDIUM 6.5
CVE-2025-14947

The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_c…

Mitigation only
Fix from $1,600 2026-01-23
Unclassified MEDIUM 5.3
CVE-2026-24633

Missing Authorization vulnerability in Passionate Brains Add Expires Headers & Optimized Minify add-expires-headers allows Exploiting Incorrectly Con…

Mitigation only
Fix from $1,600 2026-01-23
Unclassified MEDIUM 5.4
CVE-2026-24622

Missing Authorization vulnerability in Sergiy Dzysyak Suggestion Toolkit suggestion-toolkit allows Exploiting Incorrectly Configured Access Control S…

Mitigation only
Fix from $1,600 2026-01-23
Unclassified MEDIUM 5.3
CVE-2026-24625

Missing Authorization vulnerability in Imaginate Solutions File Uploads Addon for WooCommerce woo-addon-uploads allows Exploiting Incorrectly Configu…

Mitigation only
Fix from $1,600 2026-01-23
Unclassified MEDIUM 5.3
CVE-2026-24613

Missing Authorization vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart ecwid-shopping-cart allows Exploiting Incorrec…

No fix yet
Fix from $1,600 2026-01-23
Unclassified MEDIUM 5.3
CVE-2026-24615

Missing Authorization vulnerability in themebeez Cream Magazine cream-magazine allows Exploiting Incorrectly Configured Access Control Security Level…

Mitigation only
Fix from $1,600 2026-01-23
Unclassified MEDIUM 6.5
CVE-2026-24616

Missing Authorization vulnerability in Damian WP Popups wp-popups-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This i…

Mitigation only
Fix from $1,600 2026-01-23