| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-15485 | Hig | 0.53 | 8.2 | 0.00 | Sep 2, 2026 | The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc | ||
| CVE-2025-15481 | Med | 0.34 | 5.3 | 0.00 | Sep 2, 2026 | The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails. | ||
| CVE-2025-13398 | 0.00 | — | — | Sep 2, 2026 | Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned to the same unauthenticated privilege escalation vulnerability in the DesignThemes LMS WordPress plugin. All CVE users should reference CVE-2025-13542 instead of this ID. | |||
| CVE-2024-7956 | — | Hig | 0.49 | — | 0.00 | Sep 2, 2026 | A vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. To exploit this vulnerability the threat actor must have basic user privileges. If exploited, the threat actor can modify and delete the project. | |
| CVE-2024-3773 | Med | 0.38 | 5.9 | 0.00 | Sep 2, 2026 | The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored… | ||
| CVE-2023-3360 | Low | 0.21 | 3.3 | 0.00 | Sep 2, 2026 | The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog. | ||
| CVE-2026-81269 | Med | 0.27 | 5.3 | 0.00 | Sep 2, 2026 | Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13. | ||
| CVE-2026-81205 | Med | 0.27 | 5.3 | 0.00 | Sep 2, 2026 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1. | ||
| CVE-2026-81201 | Med | 0.33 | 6.1 | 0.00 | Sep 2, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS. This issue affects Monster Menus versions: from 0.0.0 to 9.5.3. | ||
| CVE-2026-81168 | Low | 0.17 | 3.7 | 0.00 | Sep 2, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2. | ||
| CVE-2026-81167 | Med | 0.24 | 4.8 | 0.00 | Sep 2, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25. | ||
| CVE-2026-81166 | Med | 0.27 | 5.3 | 0.00 | Sep 2, 2026 | Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1. | ||
| CVE-2026-81165 | Med | 0.27 | 5.3 | 0.00 | Sep 2, 2026 | Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18. | ||
| CVE-2026-81164 | Med | 0.28 | 5.4 | 0.00 | Sep 2, 2026 | Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5. | ||
| CVE-2026-81162 | Med | 0.27 | 5.3 | 0.00 | Sep 2, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1. | ||
| CVE-2026-81161 | Low | 0.21 | 3.3 | 0.00 | Sep 2, 2026 | Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0. | ||
| CVE-2026-81160 | Med | 0.40 | 6.1 | 0.00 | Sep 2, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0. | ||
| CVE-2026-81159 | Low | 0.24 | 3.7 | 0.00 | Sep 2, 2026 | Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0. | ||
| CVE-2026-81158 | Med | 0.34 | 5.3 | 0.00 | Sep 2, 2026 | Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0. | ||
| CVE-2026-76782 | Hig | 0.47 | 7.3 | 0.00 | Sep 2, 2026 | Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. | ||
| CVE-2026-76759 | Hig | 0.47 | 7.3 | 0.00 | Sep 2, 2026 | Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. | ||
| CVE-2026-76758 | Med | 0.38 | 5.9 | 0.00 | Sep 2, 2026 | Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*. | ||
| CVE-2026-76757 | Med | 0.38 | 5.9 | 0.00 | Sep 2, 2026 | Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. | ||
| CVE-2026-76756 | Med | 0.38 | 5.9 | 0.00 | Sep 2, 2026 | Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. | ||
| CVE-2026-76755 | Med | 0.38 | 5.9 | 0.00 | Sep 2, 2026 | Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. | ||
| CVE-2026-73478 | Med | 0.27 | 5.3 | 0.00 | Sep 2, 2026 | Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1. | ||
| CVE-2026-73477 | Med | 0.27 | 5.3 | 0.00 | Sep 2, 2026 | Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1. | ||
| CVE-2026-73476 | Med | 0.28 | 5.4 | 0.00 | Sep 2, 2026 | Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13. | ||
| CVE-2026-73475 | Cri | 0.52 | 9.1 | 0.00 | Sep 2, 2026 | Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3. | ||
| CVE-2026-73474 | Med | 0.27 | 5.3 | 0.00 | Sep 2, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2. | ||
| CVE-2026-18986 | Med | 0.31 | 4.8 | 0.00 | Sep 2, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from 0.0.0 to 2.16.0. | ||
| CVE-2026-16647 | Med | 0.20 | 4.1 | 0.00 | Sep 2, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4. | ||
| CVE-2026-76594 | imp | 0.53 | 8.1 | — | Sep 2, 2026 | advisor-backend: advisor-backend: Unauthenticated /private/import_content/ endpoint allows global rule-catalogue overwrite | ||
| CVE-2026-76595 | cri | 0.59 | — | — | Sep 2, 2026 | advisor-backend: Unsafe YAML deserialization of associate-editable Task playbook (yaml.Loader) | ||
| CVE-2026-84835 | Med | 0.34 | 5.3 | 0.00 | Sep 2, 2026 | Missing Authorization vulnerability in DimaFreund Rentsyst allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rentsyst: from n/a through 2.1.2. | ||
| CVE-2026-84808 | Med | 0.21 | 4.3 | 0.00 | Sep 2, 2026 | Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with view_other_timesheet permission can list timesheets using activities restricted to teams they… | ||
| CVE-2026-84807 | Med | 0.28 | 5.4 | 0.00 | Sep 2, 2026 | Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team creation endpoints. An authenticated user with project permission-management privileges can create or use a customer, project, or activity whose name matches… | ||
| CVE-2026-84806 | Med | 0.28 | 5.4 | 0.00 | Sep 2, 2026 | Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints that allows authenticated users with team edit permissions and read-only access to grant team access to customers, projects, or activities. Attackers can exploit insufficient permission… | ||
| CVE-2026-84805 | Med | 0.21 | 4.3 | 0.00 | Sep 2, 2026 | Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privilege users in the PATCH /api/users/{id}/preferences endpoint. Although the web interface gates these employment-contract fields behind the contract_other_profile admin… | ||
| CVE-2026-84804 | Med | 0.28 | 5.4 | 0.00 | Sep 2, 2026 | Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and customers via API endpoints. Authenticated users with edit_team permission can revoke team access without the required permissions_activity check, bypassing… | ||
| CVE-2026-84803 | Cri | 0.52 | 9.0 | 0.00 | Sep 2, 2026 | SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can upload files with extensions like .xht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable… | ||
| CVE-2026-84802 | Med | 0.21 | 4.3 | 0.00 | Sep 2, 2026 | Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit POST requests to the assets/move-info endpoint with arbitrary… | ||
| CVE-2026-84801 | Hig | 0.50 | 8.8 | 0.00 | Sep 2, 2026 | Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator accounts. Attackers can generate a valid reset URL for any admin… | ||
| CVE-2026-84800 | Hig | 0.39 | 7.1 | 0.00 | Sep 2, 2026 | Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, the target asset is resolved by folder and filename after the… | ||
| CVE-2026-84799 | Med | 0.21 | 4.3 | 0.00 | Sep 2, 2026 | Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can query these relations to read usernames, email addresses,… | ||
| CVE-2026-84798 | Hig | 0.39 | 7.1 | 0.00 | Sep 2, 2026 | Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element with checkForProvisionalDraft enabled and runs the deletion authorization check against the user's own… | ||
| CVE-2026-84797 | Med | 0.34 | 6.3 | 0.00 | Sep 2, 2026 | Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows authenticated users with createEntries permission to delete peer provisional drafts. Attackers can exploit the deleteProvisionalDraft parameter to… | ||
| CVE-2026-84796 | Hig | 0.50 | 8.8 | 0.00 | Sep 2, 2026 | Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to one site can read, modify, or delete entries across… | ||
| CVE-2026-84795 | Cri | 0.57 | 9.8 | 0.00 | Sep 2, 2026 | Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled… | ||
| CVE-2026-84794 | Hig | 0.39 | 7.1 | 0.00 | Sep 2, 2026 | Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing… |
- risk 0.53cvss 8.2epss 0.00
The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc
- risk 0.34cvss 5.3epss 0.00
The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails.
- CVE-2025-13398Sep 2, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned to the same unauthenticated privilege escalation vulnerability in the DesignThemes LMS WordPress plugin. All CVE users should reference CVE-2025-13542 instead of this ID.
- risk 0.49cvss —epss 0.00
A vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. To exploit this vulnerability the threat actor must have basic user privileges. If exploited, the threat actor can modify and delete the project.
- risk 0.38cvss 5.9epss 0.00
The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored…
- risk 0.21cvss 3.3epss 0.00
The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.
- risk 0.27cvss 5.3epss 0.00
Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.
- risk 0.27cvss 5.3epss 0.00
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.
- risk 0.33cvss 6.1epss 0.00
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS. This issue affects Monster Menus versions: from 0.0.0 to 9.5.3.
- risk 0.17cvss 3.7epss 0.00
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.
- risk 0.24cvss 4.8epss 0.00
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25.
- risk 0.27cvss 5.3epss 0.00
Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1.
- risk 0.27cvss 5.3epss 0.00
Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.
- risk 0.28cvss 5.4epss 0.00
Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5.
- risk 0.27cvss 5.3epss 0.00
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.
- risk 0.21cvss 3.3epss 0.00
Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.
- risk 0.40cvss 6.1epss 0.00
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0.
- risk 0.24cvss 3.7epss 0.00
Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.
- risk 0.34cvss 5.3epss 0.00
Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0.
- risk 0.47cvss 7.3epss 0.00
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
- risk 0.47cvss 7.3epss 0.00
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*.
- risk 0.38cvss 5.9epss 0.00
Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*.
- risk 0.38cvss 5.9epss 0.00
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
- risk 0.38cvss 5.9epss 0.00
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
- risk 0.38cvss 5.9epss 0.00
Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.
- risk 0.27cvss 5.3epss 0.00
Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 to 2.1.1.
- risk 0.27cvss 5.3epss 0.00
Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1.
- risk 0.28cvss 5.4epss 0.00
Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.
- risk 0.52cvss 9.1epss 0.00
Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
- risk 0.27cvss 5.3epss 0.00
Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This issue affects Entity Share Websub versions: from 0.0.0 to 1.1.2.
- risk 0.31cvss 4.8epss 0.00
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from 0.0.0 to 2.16.0.
- risk 0.20cvss 4.1epss 0.00
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
- risk 0.53cvss 8.1epss —
advisor-backend: advisor-backend: Unauthenticated /private/import_content/ endpoint allows global rule-catalogue overwrite
- risk 0.59cvss —epss —
advisor-backend: Unsafe YAML deserialization of associate-editable Task playbook (yaml.Loader)
- risk 0.34cvss 5.3epss 0.00
Missing Authorization vulnerability in DimaFreund Rentsyst allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Rentsyst: from n/a through 2.1.2.
- risk 0.21cvss 4.3epss 0.00
Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with view_other_timesheet permission can list timesheets using activities restricted to teams they…
- risk 0.28cvss 5.4epss 0.00
Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team creation endpoints. An authenticated user with project permission-management privileges can create or use a customer, project, or activity whose name matches…
- risk 0.28cvss 5.4epss 0.00
Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints that allows authenticated users with team edit permissions and read-only access to grant team access to customers, projects, or activities. Attackers can exploit insufficient permission…
- risk 0.21cvss 4.3epss 0.00
Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privilege users in the PATCH /api/users/{id}/preferences endpoint. Although the web interface gates these employment-contract fields behind the contract_other_profile admin…
- risk 0.28cvss 5.4epss 0.00
Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and customers via API endpoints. Authenticated users with edit_team permission can revoke team access without the required permissions_activity check, bypassing…
- risk 0.52cvss 9.0epss 0.00
SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can upload files with extensions like .xht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable…
- risk 0.21cvss 4.3epss 0.00
Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit POST requests to the assets/move-info endpoint with arbitrary…
- risk 0.50cvss 8.8epss 0.00
Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator accounts. Attackers can generate a valid reset URL for any admin…
- risk 0.39cvss 7.1epss 0.00
Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, the target asset is resolved by folder and filename after the…
- risk 0.21cvss 4.3epss 0.00
Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can query these relations to read usernames, email addresses,…
- risk 0.39cvss 7.1epss 0.00
Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element with checkForProvisionalDraft enabled and runs the deletion authorization check against the user's own…
- risk 0.34cvss 6.3epss 0.00
Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows authenticated users with createEntries permission to delete peer provisional drafts. Attackers can exploit the deleteProvisionalDraft parameter to…
- risk 0.50cvss 8.8epss 0.00
Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to one site can read, modify, or delete entries across…
- risk 0.57cvss 9.8epss 0.00
Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled…
- risk 0.39cvss 7.1epss 0.00
Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing…