Vulnerability index

Browse CVEs

6,913 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
MEDIUM 5.3 CVE-2025-15510 The NEX-Forms – Ultimate Forms Plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the NF5_Export_… Mitigation only Fix from $1,6002026-01-31 MEDIUM 6.5 CVE-2026-21865 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can convert some personal… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 MEDIUM 5.3 CVE-2025-68479 Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some subscription endpoints lack pro… Discourse 3.5.4 / 2025.11.2+ Fix from $1,6002026-01-28 HIGH 7.5 CVE-2026-1280 The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability check on the 'wpfm_send_file_in… Mitigation only Fix from $1,9502026-01-28 MEDIUM 5.3 CVE-2025-15511 The Rupantorpay plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_webhook() fun… Mitigation only Fix from $1,6002026-01-28 HIGH 8.8 CVE-2025-14386 The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authenticati… Mitigation only Fix from $1,9502026-01-28 MEDIUM 5.3 CVE-2026-1054 The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0.7.4. This is due to missing n… Mitigation only Fix from $1,6002026-01-28 MEDIUM 5.3 CVE-2026-0825 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to authorization bypass due to missing capability checks… Mitigation only Fix from $1,6002026-01-28 HIGH 7.3 CVE-2026-0832 The New User Approve plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on … Mitigation only Fix from $1,9502026-01-28 MEDIUM 5.3 CVE-2026-1310 The Simple calendar for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.6. This is du… Mitigation only Fix from $1,6002026-01-28 MEDIUM 6.5 CVE-2026-24134 StudioCMS is a server-side-rendered, Astro native, headless content management system. Versions prior to 0.2.0 contain a Broken Object Level Authoriz… Studiocms 0.2.0+ Fix from $1,6002026-01-28 MEDIUM 5.3 CVE-2025-14971 The Link Invoice Payment for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… Mitigation only Fix from $1,6002026-01-27 MEDIUM 5.3 CVE-2026-0593 The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… Mitigation only Fix from $1,6002026-01-24 MEDIUM 5.4 CVE-2026-1103 The AIKTP plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the /aiktp/getToken REST API… Mitigation only Fix from $1,6002026-01-24 MEDIUM 5.3 CVE-2025-14843 The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in all versions up to, and inclu… Mitigation only Fix from $1,6002026-01-24 MEDIUM 5.3 CVE-2025-14609 The Wise Analytics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.9. This is due to missing ca… Mitigation only Fix from $1,6002026-01-24 MEDIUM 5.3 CVE-2025-14629 The Alchemist Ajax Upload plugin for WordPress is vulnerable to unauthorized media file deletion due to a missing capability check on the 'delete_fil… Mitigation only Fix from $1,6002026-01-24 MEDIUM 6.5 CVE-2026-24421 phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below have flawed authorization logic which exposes the /api/setup/backup endpoin… Phpmyfaq 4.0.17+ Fix from $1,6002026-01-24 MEDIUM 6.5 CVE-2026-24139 MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below do not safeguard against authorization bypass, al… Mytube after 1.7.78 Fix from $1,6002026-01-24 CRITICAL 9.4 CVE-2025-52024 A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthenticated us… Gemscms Backend after 2025-05-28 Fix from $2,3002026-01-23 HIGH 7.5 CVE-2025-70986 Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access sensitive department data. Ruoyi No fix yet Fix from $1,9502026-01-23 CRITICAL 9.9 CVE-2025-70983 Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges. Springblade Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.1 CVE-2025-70985 Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope. Ruoyi No fix yet Fix from $2,3002026-01-23 MEDIUM 6.5 CVE-2025-14947 The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_c… Mitigation only Fix from $1,6002026-01-23 MEDIUM 5.3 CVE-2026-24633 Missing Authorization vulnerability in Passionate Brains Add Expires Headers & Optimized Minify add-expires-headers allows Exploiting Incorrectly Con… Mitigation only Fix from $1,6002026-01-23 MEDIUM 5.4 CVE-2026-24622 Missing Authorization vulnerability in Sergiy Dzysyak Suggestion Toolkit suggestion-toolkit allows Exploiting Incorrectly Configured Access Control S… Mitigation only Fix from $1,6002026-01-23 MEDIUM 5.3 CVE-2026-24625 Missing Authorization vulnerability in Imaginate Solutions File Uploads Addon for WooCommerce woo-addon-uploads allows Exploiting Incorrectly Configu… Mitigation only Fix from $1,6002026-01-23 MEDIUM 5.3 CVE-2026-24613 Missing Authorization vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart ecwid-shopping-cart allows Exploiting Incorrec… No fix yet Fix from $1,6002026-01-23 MEDIUM 5.3 CVE-2026-24615 Missing Authorization vulnerability in themebeez Cream Magazine cream-magazine allows Exploiting Incorrectly Configured Access Control Security Level… Mitigation only Fix from $1,6002026-01-23 MEDIUM 6.5 CVE-2026-24616 Missing Authorization vulnerability in Damian WP Popups wp-popups-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This i… Mitigation only Fix from $1,6002026-01-23