Total
6931 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-24613 | 2026-01-26 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart ecwid-shopping-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ecwid Shopping Cart: from n/a through <= 7.0.5.
|
|||||
| CVE-2026-24587 | 2026-01-26 | N/A | 5.4 MEDIUM | ||
|
Missing Authorization vulnerability in kutsy AJAX Hits Counter + Popular Posts Widget ajax-hits-counter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AJAX Hits Counter + Popular Posts Widget: from n/a through <= 0.10.210305.
|
|||||
| CVE-2026-24619 | 2026-01-26 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in PopCash PopCash.Net Code Integration Tool popcashnet-code-integration-tool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PopCash.Net Code Integration Tool: from n/a through <= 1.8.
|
|||||
| CVE-2026-24625 | 2026-01-26 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Imaginate Solutions File Uploads Addon for WooCommerce woo-addon-uploads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects File Uploads Addon for WooCommerce: from n/a through <= 1.7.3.
|
|||||
| CVE-2026-24561 | 2026-01-26 | N/A | 5.4 MEDIUM | ||
|
Missing Authorization vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentBoards: from n/a through <= 1.91.1.
|
|||||
| CVE-2025-14947 | 2026-01-26 | N/A | 6.5 MEDIUM | ||
|
The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_callback_create_bunny_stream_video`, `ajax_callback_get_bunny_stream_video`, and `ajax_callback_delete_bunny_stream_video` functions in all versions up to, and including, 4.6.4. This makes it possible for unauthenticated attackers to create and delete videos on the Bunny Stream CDN associated with the victim's account, provided they can obtain a vali ...
Show More |
|||||
| CVE-2025-15516 | 2026-01-26 | N/A | 4.3 MEDIUM | ||
|
The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_callback_store_user_meta() function in versions 4.1.0 to 4.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary string-based user meta keys for their own account.
|
|||||
| CVE-2025-14609 | 2026-01-26 | N/A | 5.3 MEDIUM | ||
|
The Wise Analytics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.9. This is due to missing capability checks on the REST API endpoint '/wise-analytics/v1/report'. This makes it possible for unauthenticated attackers to access sensitive analytics data including administrator usernames, login timestamps, visitor tracking information, and business intelligence data via the 'name' parameter granted they can send unauthenticated requests.
|
|||||
| CVE-2026-0687 | 2026-01-26 | N/A | 4.3 MEDIUM | ||
|
The Meta-box GalleryMeta plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mb_gallery' custom post type in all versions up to, and including, 3.0.1. This makes it possible for authenticated attackers, with Author-level access and above, to create and publish galleries.
|
|||||
| CVE-2025-14629 | 2026-01-26 | N/A | 5.3 MEDIUM | ||
|
The Alchemist Ajax Upload plugin for WordPress is vulnerable to unauthorized media file deletion due to a missing capability check on the 'delete_file' function in all versions up to, and including, 1.1. This makes it possible for unauthenticated attackers to delete arbitrary WordPress media attachments.
|
|||||
| CVE-2026-0593 | 2026-01-26 | N/A | 5.3 MEDIUM | ||
|
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify global map engine settings.
|
|||||
| CVE-2025-14843 | 2026-01-26 | N/A | 5.3 MEDIUM | ||
|
The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in all versions up to, and including, 1.2.9. This is due to a lack of authentication and authorization checks in the 'handle_checkout_redirecturl_response' function. This makes it possible for unauthenticated attackers to cancel arbitrary WooCommerce orders by sending a crafted request with a valid order ID.
|
|||||
| CVE-2026-1103 | 2026-01-26 | N/A | 5.4 MEDIUM | ||
|
The AIKTP plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the /aiktp/getToken REST API endpoint in all versions up to, and including, 5.0.04. The endpoint uses the 'verify_user_logged_in' as a permission callback, which only checks if a user is logged in, but fails to verify if the user has administrative capabilities. This makes it possible for authenticated attackers with Subscriber-level access and above to retrieve the administra ...
Show More |
|||||
| CVE-2023-47762 | 1 Wpdeveloper | 1 Betterdocs | 2026-01-23 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in WPDeveloper BetterDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BetterDocs: from n/a through 2.5.2.
|
|||||
| CVE-2025-30880 | 1 Joomsky | 1 Js Help Desk | 2026-01-23 | N/A | 7.5 HIGH |
|
Missing Authorization vulnerability in JoomSky JS Help Desk allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JS Help Desk: from n/a through 2.9.2.
|
|||||
| CVE-2025-31868 | 1 Joomsky | 1 Js Job Manager | 2026-01-23 | N/A | 5.3 MEDIUM |
|
Missing Authorization vulnerability in JoomSky JS Job Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JS Job Manager: from n/a through 2.0.2.
|
|||||
| CVE-2022-46838 | 1 Joomsky | 1 Js Help Desk | 2026-01-23 | N/A | 9.1 CRITICAL |
|
Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.
|
|||||
| CVE-2022-46840 | 1 Joomsky | 1 Js Help Desk | 2026-01-23 | N/A | 5.4 MEDIUM |
|
Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.
|
|||||
| CVE-2022-47176 | 1 Averta | 1 Depicter Slider | 2026-01-23 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in Depicter Slider and Popup by Averta Depicter Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Depicter Slider: from n/a through 1.9.0.
|
|||||
| CVE-2023-44258 | 1 Schemaapp | 1 Schema App Structured Data | 2026-01-23 | N/A | 5.3 MEDIUM |
|
Missing Authorization vulnerability in Schema App Schema App Structured Data allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Schema App Structured Data: from n/a through 1.23.1.
|
|||||
| CVE-2023-45104 | 1 Wpdeveloper | 1 Betterlinks | 2026-01-23 | N/A | 7.3 HIGH |
|
Missing Authorization vulnerability in WPDeveloper BetterLinks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BetterLinks: from n/a through 1.6.0.
|
|||||
| CVE-2023-47179 | 1 Byconsole | 1 Wooodt Lite | 2026-01-23 | N/A | 8.8 HIGH |
|
Missing Authorization vulnerability in ByConsole WooODT Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooODT Lite: from n/a through 2.4.6.
|
|||||
| CVE-2023-39994 | 1 Reputeinfosystems | 1 Armember | 2026-01-23 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in Repute InfoSystems ARMember Premium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ARMember Premium: from n/a through 5.9.2.
|
|||||
| CVE-2025-59968 | 1 Juniper | 19 Space Security Director, Srx1500, Srx1600 and 16 more | 2026-01-23 | N/A | 8.6 HIGH |
|
A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated network-based attacker to read or modify metadata via the web interface.
Tampering with this metadata can result in managed SRX Series devices permitting network traffic that should otherwise be blocked by policy, effectively bypassing intended security controls.
This issue affects Junos Space Security Director
* all versions prior to 24.1R3 Patch V4
This issue doe ...
Show More |
|||||
| CVE-2024-31270 | 1 Reputeinfosystems | 1 Arforms Form Builder | 2026-01-23 | N/A | 7.6 HIGH |
|
Missing Authorization vulnerability in Repute InfoSystems ARForms Form Builder.This issue affects ARForms Form Builder: from n/a through 1.6.1.
|
|||||
| CVE-2023-47788 | 1 Automattic | 1 Jetpack | 2026-01-23 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.
|
|||||
| CVE-2025-52954 | 1 Juniper | 1 Junos Os Evolved | 2026-01-23 | N/A | 7.8 HIGH |
|
A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Juniper Networks Junos OS Evolved allows a local, low-privileged user to gain root privileges, leading to a system compromise.
Any low-privileged user with the capability to send packets over the internal VRF can execute arbitrary Junos commands and modify the configuration, and thus compromise the system.
This issue affects Junos OS Evolved:
* All versions before 22.2R3-S7-EVO,
* from 22. ...
Show More |
|||||
| CVE-2025-14757 | 1 Stylemixthemes | 1 Cost Calculator Builder | 2026-01-23 | N/A | 5.3 MEDIUM |
|
The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions up to, and including, 3.6.9 only when used in combination with Cost Calculator Builder PRO. This is due to the complete_payment AJAX action being registered via wp_ajax_nopriv, making it accessible to unauthenticated users, and the complete() function only verifying a nonce without checking user capabilities or order ownership. Since nonces are exposed to all visitors via windo ...
Show More |
|||||
| CVE-2025-14457 | 1 Codedropz | 1 Contact Form 7 | 2026-01-23 | N/A | 3.7 LOW |
|
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete arbitrary uploaded files when the "Send attachments as links" setting is enabled.
|
|||||
| CVE-2025-39353 | 1 Themegoods | 1 Grand Restaurant | 2026-01-22 | N/A | 5.3 MEDIUM |
|
Missing Authorization vulnerability in ThemeGoods Grand Restaurant WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant WordPress: from n/a through 7.0.
|
|||||
| CVE-2025-39352 | 1 Themegoods | 1 Grand Restaurant | 2026-01-22 | N/A | 8.2 HIGH |
|
Missing Authorization vulnerability in ThemeGoods Grand Restaurant WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant WordPress: from n/a through 7.0.
|
|||||
| CVE-2025-13781 | 1 Gitlab | 1 Gitlab | 2026-01-22 | N/A | 6.5 MEDIUM |
|
GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to modify instance-wide AI feature provider settings by exploiting missing authorization checks in GraphQL mutations.
|
|||||
| CVE-2023-47180 | 1 Xlplugins | 1 Finale | 2026-01-22 | N/A | 6.5 MEDIUM |
|
Missing Authorization vulnerability in XLPlugins Finale Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Finale Lite: from n/a through 2.16.0.
|
|||||
| CVE-2024-54217 | 1 Reputeinfosystems | 1 Arforms | 2026-01-22 | N/A | 5.4 MEDIUM |
|
Missing Authorization vulnerability in Repute info systems ARForms.This issue affects ARForms: from n/a through 6.4.1.
|
|||||
| CVE-2026-0506 | 1 Sap | 1 Netweaver Application Server Abap | 2026-01-22 | N/A | 8.1 HIGH |
|
Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs and invoke system functionality exposed via FORMs, resulting in a high impact on integrity and availability, while confidentiality remains unaffected.
|
|||||
| CVE-2025-13772 | 1 Gitlab | 1 Gitlab | 2026-01-22 | N/A | 7.1 HIGH |
|
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorized namespaces by manipulating namespace identifiers in API requests.
|
|||||
| CVE-2025-64729 | 1 Aveva | 1 Process Optimization | 2026-01-22 | N/A | 8.1 HIGH |
|
The vulnerability, if exploited, could allow an authenticated miscreant
(OS Standard User) to tamper with Process Optimization project files,
embed code, and escalate their privileges to the identity of a victim
user who subsequently interacts with the project files.
|
|||||
| CVE-2025-39482 | 1 Imithemes | 1 Eventer | 2026-01-22 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in imithemes Eventer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eventer: from n/a before 3.11.4.
|
|||||
| CVE-2024-37415 | 1 E2pdf | 1 E2pdf | 2026-01-21 | N/A | 5.4 MEDIUM |
|
Missing Authorization vulnerability in E2Pdf.Com allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects e2pdf: from n/a through 1.20.27.
|
|||||
| CVE-2024-37440 | 1 Church Admin Project | 1 Church Admin | 2026-01-21 | N/A | 4.3 MEDIUM |
|
Missing Authorization vulnerability in Andy Moyle Church Admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through 4.4.4.
|
|||||