CVE-2025-65096Medium· 4.3▾ SunlitRomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4.1-beta.2, users can read private collections / smart collections belonging to other use…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4.1-beta.2, users can read private collections / smart collections belonging to other users by directly accessing their IDs via API. No ownership verification or checking if the collection is public/private before returning collection data. This vulnerability is fixed in 4.4.1 and 4.4.1-beta.2.
romm < 4.4.1romm = 4.4.1Upgrade past the affected range:
romm 4.4.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-65097Medium· 6.5RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface
CVE-2026-20897Critical· 9.1Gitea does not properly validate repository ownership when deleting Git LFS locks
CVE-2025-65027High· 7.6RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface
CVE-2026-1609High· 8.1A flaw was found in Keycloak
CVE-2026-20736High· 7.5Gitea does not properly verify repository context when deleting attachments
CVE-2026-20912Critical· 9.1Gitea does not properly validate repository ownership when linking attachments to releases