CVE-2025-66027Medium· 6.5▾ SunlitRallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant details, including names and email addresses through the /api/trpc/polls.get,polls.participan…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerability exposes participant details, including names and email addresses through the /api/trpc/polls.get,polls.participants.list endpoint, even when Pro privacy features are enabled. This bypasses intended privacy controls that should prevent participants from viewing other users’ personal information. This issue has been patched in version 4.5.6.
rallly < 4.5.6Upgrade past the affected range:
rallly 4.5.6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92565Medium· 5.3Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers
CVE-2025-14528Medium· 5.3A vulnerability was detected in D-Link DIR-803 up to 1.04
CVE-2025-14286Medium· 5.3A vulnerability was determined in Tenda AC9 15.03.05.14_multi
CVE-2025-14197Medium· 5.3A security vulnerability has been detected in Verysync 微力同步 up to 2.21.3
CVE-2025-15082Medium· 5.3A vulnerability was found in TOZED ZLT M30s up to 1.47
CVE-2026-105635High· 7.4Plane is an open-source project management tool