CWE-285— Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
1,506 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 22 of 31
- CVE-2025-65963MEDIUMCVSS 5.4EG 5.42025-11-26
Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow non-member users to create new folders, up- and download files as a ZIP archive in public s…
- CVE-2025-65966HIGHCVSS 8.1EG 8.12025-11-26
OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can create new accounts through a direct API request instead of being restricted to the intended interface. This issue has been…
- CVE-2025-66290MEDIUMCVSS 4.3EG 4.32025-11-29
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitment attachment retrieval endpoint does not enforce the required authorization checks before serving candidate files. …
- CVE-2025-66291MEDIUMCVSS 4.3EG 4.32025-11-29
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment retrieval endpoint in the Recruitment module serves files based solely on an authenticated session and user-supplied ide…
- CVE-2025-66301CRITICALCVSS 9.6EG 9.62025-12-01
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permissions to change basic content on the fo…
- CVE-2025-6639MEDIUMCVSS 5.4EG 5.42025-10-25
The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.8.3 due to missing validation on a user controlled key when viewing a…
- CVE-2025-6702MEDIUMCVSS 5.3EG 5.32025-06-26
A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown function of the file /wx/comment/post. The manipulation of the argument adminComment leads to improper authorization. It i…
- CVE-2025-6713HIGHCVSS 6.5EG 7.72025-07-07
An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further a…
- CVE-2025-67259MEDIUMCVSS 6.5EG 6.52026-04-24
A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user can access unauthorized course-level information by modifying intercepted API requests. Changing a captured POST reque…
- CVE-2025-6735HIGHCVSS 8.8EG 8.82025-06-27
A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file /admin-cp/imports of the component Import Page. The manipulation leads to improper authorization. It is possible to lau…
- CVE-2025-6736HIGHCVSS 8.8EG 8.82025-06-27
A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-cp/theme/install of the component Add New Themes Page. The manipulation leads to improper …
- CVE-2025-67603MEDIUMCVSS 5.1EG 5.12026-01-08
A Improper Authorization vulnerability in Foomuuri llows arbitrary users to influence the firewall configuration.This issue affects Foomuuri: from ? before 0.31.
- CVE-2025-67715MEDIUMCVSS 4.3EG 4.32025-12-16
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue.
- CVE-2025-68481MEDIUMCVSS 5.9EG 5.92025-12-19
FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login state tokens are completely stateless and carry no per-request entropy or any data that c…
- CVE-2025-68712MEDIUMCVSS 5.5EG 5.52026-05-27
SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric mechanisms, the lock is implemented with a …
- CVE-2025-71242MEDIUMCVSS 6.5EG 6.52026-02-19
SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does not properly check authorization when displaying content of articles and sections (rubriques) in AJAX-loaded fragments, …
- CVE-2025-7221MEDIUMCVSS 4.3EG 4.32025-08-21
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the give_update_payment_status() function in all versions up to, and inclu…
- CVE-2025-7778CRITICALCVSS 9.8EG 9.82025-08-15
The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and improper path validation within the delete_files() function in all versions up to, and including, 1.6.12. This makes it p…
- CVE-2025-7938MEDIUMCVSS 4.3EG 4.32025-07-21
A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0 and classified as critical. This issue affects the function updateGoods of the file GoodsController.java. The manipulation leads to authorization bypass. The at…
- CVE-2025-7947HIGHCVSS 8.1EG 8.12025-07-22
A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component Account Handler. The manipulation of the argument ID leads to improper authorization. It i…
- CVE-2025-8057MEDIUMCVSS 6.5EG 6.52025-09-16
Authorization Bypass Through User-Controlled Key, Externally Controlled Reference to a Resource in Another Sphere, Improper Authorization vulnerability in Patika Global Technologies HumanSuite allows Exploiting Trust in Client. This issue…
- CVE-2025-8147MEDIUMCVSS 4.3EG 4.32025-08-29
The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on the lwscache_activatePlugin() function in all versions up to, and including, 2.8.5. This makes it possible for authentica…
- CVE-2025-8261CRITICALCVSS 9.8EG 9.82025-07-28
A weakness has been identified in Vaelsys VaelsysV4 4.1.0. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the component User Creation Handler. Executing a manipulation can lead to improper authorization. The …
- CVE-2025-8401MEDIUMCVSS 4.3EG 4.32025-07-31
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.1 via the 'get_post_data' function. This makes it possible for authenticated attac…
- CVE-2025-8532MEDIUMCVSS 6.4EG 6.42025-09-19
Authorization Bypass Through User-Controlled Key, Improper Authorization vulnerability in Bimser Solution Software Trade Inc. EBA Document and Workflow Management System allows Forceful Browsing. This issue affects eBA Document and Workfl…
- CVE-2025-8547MEDIUMCVSS 5.3EG 5.32025-08-05
A vulnerability has been found in atjiu pybbs up to 6.0.0 and classified as critical. This vulnerability affects unknown code of the component Email Verification Handler. The manipulation leads to improper authorization. The attack can be …
- CVE-2025-8755MEDIUMCVSS 5.3EG 5.32025-08-09
A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the function detail of the file UmsMemberController.java of the component com.macro.mall.portal.controller. The manipulation of the …
- CVE-2025-8756HIGHCVSS 8.8EG 8.82025-08-09
A vulnerability has been found in TDuckCloud tduck-platform up to 5.1 and classified as critical. Affected by this vulnerability is the function preHandle of the file /manage/ of the component com.tduck.cloud.api.web.interceptor.Authorizat…
- CVE-2025-8789MEDIUMCVSS 4.3EG 4.32025-08-10
A vulnerability was found in Portabilis i-Educar up to 2.9.0. It has been classified as problematic. This affects an unknown part of the file /module/Api/Diario of the component API Endpoint. The manipulation leads to authorization bypass.…
- CVE-2025-8790MEDIUMCVSS 4.3EG 4.32025-08-10
A vulnerability was found in Portabilis i-Educar up to 2.9.0. It has been declared as critical. This vulnerability affects unknown code of the file /module/Api/pessoa of the component API Endpoint. The manipulation of the argument ID leads…
- CVE-2025-8791MEDIUMCVSS 6.3EG 6.32025-08-10
A vulnerability was found in LitmusChaos Litmus up to 3.19.0. It has been rated as critical. This issue affects some unknown processing of the file /auth/list_projects. The manipulation of the argument role leads to improper authorization.…
- CVE-2025-8794HIGHCVSS 7.8EG 7.82025-08-10
A vulnerability, which was classified as problematic, has been found in LitmusChaos Litmus up to 3.19.0. Affected by this issue is some unknown functionality of the component LocalStorage Handler. The manipulation of the argument projectID…
- CVE-2025-8839HIGHCVSS 8.8EG 8.82025-08-11
A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endpoint. The manipulation leads to improper authorization. The attack may be initiated remote…
- CVE-2025-8840MEDIUMCVSS 5.4EG 5.42025-08-11
A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoint. The manipulation of the argument ids leads to improper authorization. It is possible t…
- CVE-2025-9151MEDIUMCVSS 6.3EG 6.32025-08-19
A security flaw has been discovered in LiuYuYang01 ThriveX-Blog up to 3.1.7. Affected by this vulnerability is the function updateJsonValueByName of the file /web_config/json/name/web. Performing manipulation results in improper authorizat…
- CVE-2025-9294MEDIUMCVSS 4.3EG 4.32026-01-06
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the qsm_dashboard_delete_result function in all versions up to, and includ…
- CVE-2025-9602MEDIUMCVSS 6.5EG 6.52025-08-29
A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation results in improper authorization. The attack is possible to be carried out remotely. The exploi…
- CVE-2025-9609HIGHCVSS 8.8EG 8.82025-08-29
A vulnerability was found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /educacenso/consulta. The manipulation results in improper authorization. The attack can be executed remotely. The exploit has…
- CVE-2025-9687HIGHCVSS 8.8EG 8.82025-08-30
A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/HistoricoEscolar/processamentoApi. Executing manipulation can lead to improper authorization. The attack may be performed…
- CVE-2025-9760HIGHCVSS 8.8EG 8.82025-09-01
A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Api/matricula of the component Matricula API. Executing manipulation can lead to improper authorization. It is possible to l…
- CVE-2025-9835MEDIUMCVSS 4.3EG 4.32025-09-02
A vulnerability has been found in macrozheng mall up to 1.0.3. This affects the function cancelOrder of the file /order/cancelUserOrder. The manipulation of the argument orderId leads to authorization bypass. The attack can be initiated re…
- CVE-2025-9836MEDIUMCVSS 4.3EG 4.32025-09-02
A vulnerability was found in macrozheng mall up to 1.0.3. This vulnerability affects the function paySuccess of the file /order/paySuccess. The manipulation of the argument orderId results in authorization bypass. The attack can be launche…
- CVE-2025-9936MEDIUMCVSS 4.3EG 4.32025-09-04
A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the file /ad/queryAll. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. …
- CVE-2025-9937MEDIUMCVSS 5.4EG 5.42025-09-04
A security flaw has been discovered in elunez eladmin 1.1. Impacted is the function deleteFile of the component LocalStorageController. The manipulation results in improper authorization. The attack may be performed from remote. The exploi…
- CVE-2025-9988MEDIUMCVSS 4.3EG 4.32026-05-13
The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the create_advertiser AJAX action in all versions up to, and including, 1.53.1. This makes it possible for authenticated attacke…
- CVE-2026-0017HIGHCVSS 7.7EG 7.72026-03-02
In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction …
- CVE-2026-0072HIGHCVSS 7.8EG 7.82026-06-01
In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i…
- CVE-2026-0574MEDIUMCVSS 8.8EG 6.32026-01-04
A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function saveUserRole of the file warehouse\src\main\java\com\yeqifu\sys\controller\UserController.java of the component Re…
- CVE-2026-10070MEDIUMCVSS 4.7EG 4.72026-05-29
A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of the component Super Admin Password Handler. Performing a manipulation results in improper authorization. Remote exploi…
- CVE-2026-10154MEDIUMCVSS 4.3EG 4.32026-05-30
A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is an unknown function of the file htdocs/user/messaging.php. Such manipulation of the argument ID leads to authorization bypass. The attack can …
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →