CWE-863


Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.


We have discovered 680,370 live websites that are affected by CWE-863.

Contact us to get more info









CVEs

  • Count - 126



Website Distribution by Country

Number of websites using CWE-863
United States191,279 websites



Germany64,335 websites
France42,101 websites
Japan30,003 websites
GB29,221 websites
Italy28,724 websites
Russia22,151 websites
Netherlands19,774 websites
Spain18,318 websites
Poland15,055 websites

Website Distribution by TLD

Number of websites using CWE-863
.com273,378 websites
.de34,891 websites
.org32,206 websites
.it19,951 websites
.fr18,495 websites
.ru17,665 websites
.net17,430 websites
.co.uk17,081 websites
.nl16,624 websites
.com.br11,821 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-863
DiscoveredCVEDescriptionWebsites
Nov, 2025CVE-2025-11776 Guest user can discover archived public channels464
Nov, 2025CVE-2025-41436 Unauthorized access to archived channel content via threads interface464
Nov, 2025CVE-2025-11777 Cross-team channel membership access116
Nov, 2025CVE-2025-49145 iTop admin can drop iTop database using webhooks23
Nov, 2025CVE-2025-62275 Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 202...72
Oct, 2025CVE-2025-62259 Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 th...72
Oct, 2025CVE-2025-11888 ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.4 - Incorrect Authorization to Authenticated (Editor+) License Status Update4,062
Oct, 2025CVE-2025-10545 Guest user can add unauthorized team users to private channels97
Oct, 2025CVE-2025-62243 Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 throug...68
Oct, 2025CVE-2025-7374 WP JobHunt <= 7.6 Authenticated (Custom+) Authorization Bypass1
List of the most common CVEs that are part of CWE-863
DiscoveredCVEDescriptionWebsites
Jan, 2024CVE-2022-0775 WooCommerce < 6.2.1 - Subscriber+ Arbitrary Comment Deletion237,376
Nov, 2024CVE-2024-9926 Jetpack < 13.9.1 - Subscriber+ Arbitrary Feedback Access163,456
Mar, 2025CVE-2025-31673 Drupal core - Moderately critical - Access bypass - SA-CORE-2025-002112,892
Sep, 2025CVE-2025-8944 OceanWP < 4.1.2 - Subscriber+ Limited Option Update87,655
Jan, 2023CVE-2022-45353 WordPress Betheme theme <= 26.6.1 is vulnerable to Broken Access Control40,312
Jun, 2023CVE-2023-2877 Formidable Forms < 6.3.1 - Subscriber+ Remote Code Execution11,029
Jan, 2024CVE-2023-6421 Download Manager < 3.2.83 - Unauthenticated Protected File Download Password Leak10,416
Jul, 2025CVE-2025-8068 HT Mega – Absolute Addons For Elementor <= 2.9.1 - Improper Authorization to Authenticated (Contributor+) Limited Administrator Actions8,335
Apr, 2020CVE-2020-8142 A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 b...5,683
Oct, 2025CVE-2025-11888 ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.4 - Incorrect Authorization to Authenticated (Editor+) License Status Update4,062

Websites affected by CWE-863

Top websites that are affected by CWE-863. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.**.uk GB***
*********.com United States***
*********.com United States***
***.gov United States***
****************.de Germany***
******.*******.org United States***
***.org France*,***
**************************.nl Netherlands*,***
*******.gov United States*,***
***.gov United States*,***
See full domain list