CWE-863


Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.


We have discovered 435,632 live websites that are affected by CWE-863.

Contact us to get more info









CVEs

  • Count - 5



Countries

United States105,169 websites



Germany23,930 websites
Italy23,569 websites
France23,331 websites
Russia20,656 websites
GB20,200 websites
Spain15,387 websites
Vietnam13,999 websites
Netherlands12,011 websites
Australia10,354 websites

TLDs

.com196,024 websites
.ru16,158 websites
.it15,139 websites
.co.uk11,686 websites
.de11,574 websites
.org11,372 websites
.nl9,145 websites
.fr8,615 websites
.net8,373 websites
.com.br7,997 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-863
DiscoveredCVEDescriptionWebsites
Jan, 2024CVE-2022-0775 WooCommerce < 6.2.1 - Subscriber+ Arbitrary Comment Deletion428,468
May, 2023CVE-2023-1979 Auth bypass in Web Stories for WordPress plugin91
Jan, 2023CVE-2022-45353 WordPress Betheme theme <= 26.6.1 is vulnerable to Broken Access Control7,398
Sep, 2021CVE-2021-34647 Ninja Forms <= 3.5.7 Sensitive Information Disclosure44
Sep, 2021CVE-2021-34648 Ninja Forms <= 3.5.7 Unprotected REST-API to Email Injection44
List of the most common CVEs that are part of CWE-863
DiscoveredCVEDescriptionWebsites
Jan, 2024CVE-2022-0775 WooCommerce < 6.2.1 - Subscriber+ Arbitrary Comment Deletion428,468
Jan, 2023CVE-2022-45353 WordPress Betheme theme <= 26.6.1 is vulnerable to Broken Access Control7,398
May, 2023CVE-2023-1979 Auth bypass in Web Stories for WordPress plugin91
Sep, 2021CVE-2021-34647 Ninja Forms <= 3.5.7 Sensitive Information Disclosure44
Sep, 2021CVE-2021-34648 Ninja Forms <= 3.5.7 Unprotected REST-API to Email Injection44

Websites affected by CWE-863

Top websites that are affected by CWE-863. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.com United States*,***
***.***********.com Italy*,***
***.*********.nl Netherlands*,***
***********.com United States*,***
*****************.com United States*,***
***.*************.com United States*,***
***.com United States*,***
*********.com United States*,***
*******.com United States*,***
***.**********.com United States*,***
See full domain list