Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Unclassified HIGH 7.5
CVE-2025-13384

The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.56. This is due…

Mitigation only
Fix from $1,950 2025-11-22
Unclassified MEDIUM 5.3
CVE-2025-66113

Missing Authorization vulnerability in ThemeAtelier Better Chat Support for Messenger better-chat-support allows Exploiting Incorrectly Configured Ac…

Mitigation only
Fix from $1,600 2025-11-21
Unclassified MEDIUM 5.3
CVE-2025-66114

Missing Authorization vulnerability in theme funda Show Variations as Single Products Woocommerce woo-show-single-variations-shop-category allows Exp…

Mitigation only
Fix from $1,600 2025-11-21
Unclassified MEDIUM 5.3
CVE-2025-66107

Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-for-paypal allows Exploiting I…

Mitigation only
Fix from $1,600 2025-11-21
Unclassified MEDIUM 5.3
CVE-2025-66109

Missing Authorization vulnerability in Octolize Shipping Plugins Cart Weight for WooCommerce woo-cart-weight allows Exploiting Incorrectly Configured…

Mitigation only
Fix from $1,600 2025-11-21
Unclassified MEDIUM 5.3
CVE-2025-66110

Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Exploiting Incorrectly Configured Access Control Security Levels.Thi…

Mitigation only
Fix from $1,600 2025-11-21
Unclassified MEDIUM 5.3
CVE-2025-66099

Missing Authorization vulnerability in ThemeAtelier Chat Help chat-help allows Exploiting Incorrectly Configured Access Control Security Levels.This …

Mitigation only
Fix from $1,600 2025-11-21
Unclassified MEDIUM 5.3
CVE-2025-66082

Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Leve…

Mitigation only
Fix from $1,600 2025-11-21
Unclassified MEDIUM 5.3
CVE-2025-66083

Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Leve…

Mitigation only
Fix from $1,600 2025-11-21
Unclassified MEDIUM 5.3
CVE-2025-66086

Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Se…

Mitigation only
Fix from $1,600 2025-11-21
Unclassified MEDIUM 5.3
CVE-2025-66071

Missing Authorization vulnerability in tychesoftwares Custom Order Numbers for WooCommerce custom-order-numbers-for-woocommerce allows Exploiting Inc…

Mitigation only
Fix from $1,600 2025-11-21
Unclassified MEDIUM 5.3
CVE-2025-66072

Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…

No fix yet
Fix from $1,600 2025-11-21
Unclassified MEDIUM 5.3
CVE-2025-66077

Missing Authorization vulnerability in wpWax Legal Pages legal-pages allows Exploiting Incorrectly Configured Access Control Security Levels.This iss…

No fix yet
Fix from $1,600 2025-11-21
Unclassified MEDIUM 6.5
CVE-2025-66079

Missing Authorization vulnerability in Jegstudio Gutenverse Form gutenverse-form allows Exploiting Incorrectly Configured Access Control Security Lev…

Mitigation only
Fix from $1,600 2025-11-21
Unclassified MEDIUM 5.4
CVE-2025-66063

Missing Authorization vulnerability in jgwhite33 WP Google Review Slider wp-google-places-review-slider allows Exploiting Incorrectly Configured Acce…

Mitigation only
Fix from $1,600 2025-11-21
Unclassified MEDIUM 6.5
CVE-2025-66065

Missing Authorization vulnerability in Jegstudio Gutenverse gutenverse allows Exploiting Incorrectly Configured Access Control Security Levels.This i…

Mitigation only
Fix from $1,600 2025-11-21
Seriously Simple Podcasting MEDIUM 5.3
CVE-2025-66060

Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured …

Fix: 3.14.0+
Fix from $1,600 2025-11-21
Unclassified MEDIUM 5.3
CVE-2025-12170

The Checkbox plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wp_ajax_nopriv_checkbox_clean_…

Mitigation only
Fix from $1,600 2025-11-21
Unclassified HIGH 8.8
CVE-2025-11985

The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capa…

Mitigation only
Fix from $1,950 2025-11-21
Unclassified MEDIUM 6.5
CVE-2025-10938

The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to mi…

Mitigation only
Fix from $1,600 2025-11-21
Unclassified MEDIUM 6.4
CVE-2025-11003

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due t…

Mitigation only
Fix from $1,600 2025-11-21
GitLab MEDIUM 6.5
CVE-2025-9825

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have…

Fix: 18.2.8 / 18.3.4+
Fix from $1,600 2025-11-21
Revive Adserver MEDIUM 6.5
CVE-2025-52670

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accou…

Fix: after 6.0.1
Fix from $1,600 2025-11-20
Soplanning MEDIUM 5.4
CVE-2025-62293

SOPlanning is vulnerable to Broken Access Control in /status endpoint. Due to lack of permission checks in Project Status functionality an authentica…

Fix: 1.55.00+
Fix from $1,600 2025-11-20
Alumni Management System HIGH 8.1
CVE-2025-13468

A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comm…

No fix yet
Fix from $1,950 2025-11-20
Unclassified MEDIUM 5.3
CVE-2025-12778

The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized access of data due to a missi…

Mitigation only
Fix from $1,600 2025-11-20
Pro Macros MEDIUM 6.5
CVE-2025-65089

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no v…

Fix: 1.27.0+
Fix from $1,600 2025-11-19
Rallly MEDIUM 6.5
CVE-2025-65028

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows a…

Fix: 4.5.4+
Fix from $1,600 2025-11-19
Rallly HIGH 8.1
CVE-2025-65029

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference (IDOR) vulnerability allows a…

Fix: 4.5.4+
Fix from $1,950 2025-11-19
Rallly MEDIUM 6.5
CVE-2025-65020

Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference (IDOR) vulnerability in the p…

Fix: 4.5.4+
Fix from $1,600 2025-11-19