CVE-2026-77144None▾ SunlitThe frontend management plugin attributed a newly created event to the submitting user's organizer record only when the request supplied no organizer of its own. The accompanying permission check confirmed only that the submitting user h…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
The frontend management plugin attributed a newly created event to the submitting user's organizer record only when the request supplied no organizer of its own. The accompanying permission check confirmed only that the submitting user held any organizer role. A user with frontend event management access could therefore create an event that is attributed to another organizer.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-32640Critical· 9.8SimpleEval is a library for adding evaluatable expressions into python projects
CVE-2026-93364Medium· 4.3Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save req…
CVE-2026-93477Medium· 5.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the bulk destroy and bulk update paths. Action arguments decl…
CVE-2026-55736MediumAsh: Private action arguments can be set by user input via string-keyed params and atomic changesets
CVE-2026-76086High· 8.5Formie is a Craft CMS plugin for creating forms
CVE-2026-56679High9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade