VYPR

Crayons

by WordPress

CVEs (1)

  • CVE-2026-104070CriOct 6, 2026
    risk 0.64cvss 9.8epss —

    The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to…