Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

8,672 CVEs tagged with CWE-862434 Critical, 1,954 High, 5,992 Medium, 291 Low, 1 Unrated.

CVE-2026-13250

Published Jul 11, 2026

The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3. This is due to the plugin not properly verifying that a us…

CVSS 5.3 · Medium
evidence mentions
9
Buzz score
38.0

CVE-2026-8678

Published Jul 11, 2026

The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.25.1. This is due to the plugin not properly verifying that a user…

CVSS 4.3 · Medium
evidence mentions
9
Buzz score
38.0

CVE-2026-10628

Published Jul 11, 2026

The Points and Rewards for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.10.0. This is due to the plugin not prope…

CVSS 4.3 · Medium
evidence mentions
13
Buzz score
41.4

CVE-2026-58590

Published Jul 10, 2026

Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-58589

Published Jul 10, 2026

Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49394

Published Jul 10, 2026

Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_page endpoint in Workspace because public workspaces did not r…

CVSS 7.1 · High
evidence mentions
6
Buzz score
24.5

CVE-2026-48127

Published Jul 10, 2026

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.110.0, users without write access could attach files to any doctype through file-handling API endpoints s…

CVSS 5.3 · Medium
evidence mentions
9
Buzz score
28.0

CVE-2026-47422

Published Jul 10, 2026

Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and that has since been fixed. This…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-13241

Published Jul 10, 2026

Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13240

Published Jul 10, 2026

Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13239

Published Jul 10, 2026

Missing Authorization vulnerability in Drupal WissKI allows Forceful Browsing. This issue affects WissKI versions: from 0.0.0 to 4.2.0.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-11909

Published Jul 10, 2026

Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examples for Developers versions: from 0.0.0 to 4.0.6.

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-10768

Published Jul 10, 2026

Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-57221

Published Jul 10, 2026

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.dec…

CVSS 5.3 · Medium
evidence mentions
9
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-13039

Published Jul 10, 2026

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-57850

Published Jul 10, 2026

RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera,…

CVSS 8.7 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-55476

Published Jul 10, 2026

Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_admin?}/{requestingUser?} accepts cancel_by_admin as a URL…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-54329

Published Jul 10, 2026

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory model while company_id is mass…

CVSS 8.5 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-56668

Published Jul 10, 2026

ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-type:token-exchange does not veri…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-55638

Published Jul 10, 2026

9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /codex before next.config.mjs rew…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-1667

Published Jul 10, 2026

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting in all versions up to, and including, 14.0.0 due to a…

CVSS 7.2 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-61441

Published Jul 10, 2026

PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either endpoint of a dependency edge…

CVSS 7.1 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-59796

Published Jul 10, 2026

In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 176-200 of 8,672 CVEsPage 8 of 347