VulnSea

CWE-598

CVEs classified under CWE-598, newest first.

11 CVEsRSS

CVE-2026-81632High· 7.2
5d ago

Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its o…

Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its o…

Twilightteam-alembic · ash_authentication_phoenixEPSS 0.15%via NVD
CVE-2026-55375Medium· 5.3
1w ago

canto-saas-api is a PHP library for interacting with the Canto SaaS API

canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryParams() places app_id, app_secret, refresh_token, and code in the URL query string of token POST requests, allowing …

Sunlitjleehr · canto-saas-apiEPSS 0.25%via NVD
CVE-2026-50157Medium· 6.5
1w ago

Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs

Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bear…

Sunlitauth0 · symfonyEPSS 0.50%via NVD
CVE-2026-88897Medium· 5.9
1w ago

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant…

Sunlitflextype · flextypeEPSS 0.32%via NVD
CVE-2026-61614Medium· 5.9
2w ago

SolidInvoice is an open-source invoicing platform

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a fallback to the `X-API-TOKEN` header. This causes long-lived API credent…

SunlitSolidInvoice · SolidInvoiceEPSS 0.28%via NVD
CVE-2026-63408High· 7.5
1mo ago

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API plugin JwtAuthenticator::extractBearerToken() accepts a JWT from the token URL query parameter o…

TwilightEPSS 0.36%via NVD
CVE-2026-16207Low· 3.7
2mo ago

A vulnerability was detected in django-tastypie up to 0.15.1

A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthentication of the file tastypie/authentication.py. The manipulation results in use of get request method with sensitive query strings. The a…

SunlitEPSS 0.62%via NVD
GHSA-gj2h-2fpw-fhv9Medium
2mo ago

@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration

@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration

Sunlitnuxt · @nuxt/uivia GHSA
CVE-2026-47768Medium· 5.5
3mo ago

nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)

nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)

Sunlitjuev · github.com/juev/nebula-meshEPSS 0.11%via GHSA
CVE-2026-27949Low· 2.0
5mo ago

Plane is an an open-source project management tool

Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the URL during error handling (e.g., when …

Sunlitplane · planeEPSS 0.17%via NVD
CVE-2026-25118High· 7.5
5mo ago

immich is a high performance self-hosted photo and video management solution

immich is a high performance self-hosted photo and video management solution. Prior to version 2.6.0, the Immich application is vulnerable to credential disclosure when a user authenticates to a shared album. During the authentication pr…

Twilightfuto · immichEPSS 0.45%via NVD
CWE-598 vulnerabilities (CVEs) · VulnSea