CVE-2025-50709Medium· 4.3▾ SunlitAn issue in Perplexity AI GPT-4 allows a remote attacker to obtain sensitive information via a GET parameter
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
An issue in Perplexity AI GPT-4 allows a remote attacker to obtain sensitive information via a GET parameter
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-81632High· 7.2Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its o…
CVE-2026-61614Medium· 5.9SolidInvoice is an open-source invoicing platform
CVE-2026-88897Medium· 5.9Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes
CVE-2026-63408High· 7.5Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content
CVE-2026-27949Low· 2.0Plane is an an open-source project management tool
CVE-2026-25118High· 7.5immich is a high performance self-hosted photo and video management solution