CVE-2026-107830Medium· 5.3▾ SunlitJivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction, allowing unlimited SMS sending. Attackers can load newAccount.jsp to set session attri…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Jivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction, allowing unlimited SMS sending. Attackers can load newAccount.jsp to set session attributes, then repeatedly call the endpoint to harass arbitrary phone numbers and exhaust the operator's Tencent Cloud SMS balance.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-11441Low· 3.7A vulnerability was identified in JhumanJ OpnForm up to 1.9.3
CVE-2025-12547Low· 3.7A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1
CVE-2025-13211Medium· 5.3IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.
CVE-2026-82924Medium· 5.3Improper Control of Interaction Frequency vulnerability in Pusula Communication, IT, and Internet Industry and Trade Co
CVE-2026-97300Medium· 6.5Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.
CVE-2026-105237Low· 3.7A vulnerability was detected in linlinjava litemall up to 1.8.0