Export limit exceeded: 30000 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10493 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-39751 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions. | ||||
| CVE-2026-39749 | 2026-10-06 | 6.5 Medium | ||
| Subscriber Broken Access Control in App for Cloudflare® <= 1.10.1 versions. | ||||
| CVE-2026-39723 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions. | ||||
| CVE-2026-39599 | 2026-10-06 | 4.3 Medium | ||
| Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions. | ||||
| CVE-2026-32582 | 2026-10-06 | 6.5 Medium | ||
| Contributor Broken Access Control in IATO MCP <= 1.11.0 versions. | ||||
| CVE-2026-32578 | 2026-10-06 | 7.1 High | ||
| Subscriber Broken Access Control in ECPay Ecommerce for WooCommerce <= 1.1.2606090 versions. | ||||
| CVE-2026-25433 | 2026-10-06 | 7.1 High | ||
| Subscriber Broken Access Control in WP2LEADS <= 3.5.7 versions. | ||||
| CVE-2026-105072 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions. | ||||
| CVE-2026-104386 | 2026-10-06 | 6.5 Medium | ||
| Missing Authorization vulnerability in WPFunnels Team WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 9.1.3. | ||||
| CVE-2026-103337 | 2026-10-06 | 6.5 Medium | ||
| Missing Authorization vulnerability in Kirillbdev WC Ukraine Shipping wc-ukr-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Ukraine Shipping: from n/a through 1.23.2. | ||||
| CVE-2026-103086 | 2026-10-06 | 6.5 Medium | ||
| Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.74. | ||||
| CVE-2026-103762 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-10-06 | 5.3 Medium |
| SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished notebook box IDs. Attackers with read-only or anonymous publish access can POST any open notebook ID to receive the global save-box ID and save-path template, revealing a hidden notebook's existence and creation time. | ||||
| CVE-2026-105695 | 1 Penpot | 1 Penpot | 2026-10-05 | 5.9 Medium |
| Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into the attacker's own file, team font, or project import, disclosing the uploaded bytes and deleting the victim's pending session. This issue is fixed in version 2.18.0. | ||||
| CVE-2026-105209 | 1 Zitadel | 1 Zitadel | 2026-10-05 | 9.6 Critical |
| ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account. | ||||
| CVE-2026-104979 | 1 Makeplane | 1 Plane | 2026-10-05 | 8.7 High |
| Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes description_html through Issue.objects.create(...) without calling validate_html_content from nh3. Any authenticated user, including a new user with no workspace memberships, can plant arbitrary HTML in a project that has a published DeployBoard with intake enabled. When a project member or viewer of a closed intake item clicks the planted link, the TipTap \tjavascript: parser bypass and the target="_self" click handler execute JavaScript in the viewer's session and exfiltrate a long-lived API token. This issue is fixed in 1.4.0. | ||||
| CVE-2026-104968 | 1 Makeplane | 1 Plane | 2026-10-05 | N/A |
| Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/entity-search/?query_type=user_mention returns workspace-member display names, UUIDs, and avatar URLs to any authenticated user who knows the workspace slug, even when the caller is not a workspace member. The endpoint also exposes ProjectMember rows under the same condition. SearchEndpoint in apps/api/plane/app/views/search/base.py inherits BaseAPIView with only permission_classes = [IsAuthenticated] and performs no workspace-membership check. This issue is fixed in 1.4.0. | ||||
| CVE-2026-104971 | 1 Makeplane | 1 Plane | 2026-10-05 | 8.5 High |
| Plane is an open-source project management tool. Prior to 1.4.0, DuplicateAssetEndpoint fetches a source FileAsset without limiting it to the caller's workspace, allowing cross-workspace asset duplication. WorkspaceFileAssetEndpoint and the legacy FileAssetEndpoint omit workspace authorization, allowing authenticated users to read, create, modify, or delete assets in workspaces where they are not members. Separately, WorkspaceViewViewSet.retrieve lacks the authorization decorator used by its sibling actions, exposing an unauthorized workspace-view read surface. This issue is fixed in 1.4.0. | ||||
| CVE-2026-105635 | 1 Makeplane | 1 Plane | 2026-10-05 | 7.4 High |
| Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ uses permission_classes = [AllowAny] and returns the full ProjectMemberInvite record, including its email, token, and role, to unauthenticated callers. The corresponding POST endpoint checks only whether the submitted email matches project_invite.email and does not validate the invitation token. An attacker who knows the invitation UUID can discover the invited email, register an account with that email, and accept the invitation without receiving the original invite. This issue is fixed in 1.4.0. | ||||
| CVE-2026-97304 | 2026-10-05 | 6.5 Medium | ||
| Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through 1.0.63. | ||||
| CVE-2026-104962 | 1 Makeplane | 1 Plane | 2026-10-05 | 6.5 Medium |
| Plane is an open-source project management tool. Prior to 1.4.0, GET /api/v1/workspaces/{slug}/projects/{project_id}/members/ returns the complete project-member roster, including each member's email address, first and last name, display name, avatar, and role. ProjectMemberPermission gates the endpoint, but its SAFE_METHODS branch checks only whether the caller is an active ProjectMember of any project in the workspace and does not bind the check to view.project_id. The view then filters solely by the project_id supplied in the URL. Consequently, any authenticated user who belongs to one project in a workspace, including a Guest, can read the roster of another private project in the same workspace. This issue is fixed in 1.4.0. | ||||