CVE-2025-62784Medium· 5.3▾ SunlitInventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions before 1.6.5 contain a vulnerability where any plugin using a GUI with the GuiStorageElement and allows taking out items out of that element can allow …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions before 1.6.5 contain a vulnerability where any plugin using a GUI with the GuiStorageElement and allows taking out items out of that element can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version 1.6.5.
inventorygui < 1.6.5Upgrade past the affected range:
inventorygui 1.6.5Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62782Medium· 5.3InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins
CVE-2025-62783Medium· 5.0InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins
CVE-2026-105850High· 8.8Payload is a free and open source headless content management system
CVE-2026-86198Medium· 4.2PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling
CVE-2026-45734Medium· 5.3MyBB is free and open source forum software