Venueless
by Venueless
Source repositories
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-5599 | Hig | 0.47 | — | 0.00 | Apr 5, 2026 | A user with API access and "manage users" permission in any venueless world is able to trigger deletion of user accounts in other worlds. | ||
| CVE-2026-4982 | Hig | 0.47 | — | 0.00 | Mar 27, 2026 | A user with permission "update world" in any Venueless world is able to exfiltrate chat messages from direct messages or channels in other worlds on the same server due to a bug in the reporting feature. The exploitability is limited by the fact that the attacker needs to know… | ||
| CVE-2026-12863 | Med | 0.33 | — | 0.00 | Jun 22, 2026 | An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains. | ||
| CVE-2026-12862 | Med | 0.33 | — | 0.00 | Jun 22, 2026 | Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file. | ||
| CVE-2026-13350 | Low | 0.00 | — | 0.00 | Jun 25, 2026 | Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't be allowed to create. |
- risk 0.47cvss —epss 0.00
A user with API access and "manage users" permission in any venueless world is able to trigger deletion of user accounts in other worlds.
- risk 0.47cvss —epss 0.00
A user with permission "update world" in any Venueless world is able to exfiltrate chat messages from direct messages or channels in other worlds on the same server due to a bug in the reporting feature. The exploitability is limited by the fact that the attacker needs to know…
- risk 0.33cvss —epss 0.00
An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains.
- risk 0.33cvss —epss 0.00
Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file.
- risk 0.00cvss —epss 0.00
Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't be allowed to create.