VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

667 CVEsRSS

CVE-2026-86837Medium· 5.3
2d ago

The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's primary identifier to overwrite that customer's stored …

The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's primary identifier to overwrite that customer's stored …

▾ SunlitEPSS 0.18%via NVD
CVE-2026-93399Critical· 9.1PoC
2d ago

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX ac…

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX ac…

▾ Abyssalladela · Online Scheduling and Appointment Booking System – BooklyEPSS 0.37%via NVD
CVE-2026-97721Low· 2.7
2d ago

A weakness has been identified in Sanluan PublicCMS up to 6.202506.e

A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function CmsContentAdminController of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/controller/admin/sys/SysUserA…

▾ SunlitSanluan · PublicCMSEPSS 0.24%via NVD
CVE-2026-97647Medium· 5.3
2d ago

A security vulnerability has been detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A security vulnerability has been detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This impacts an unknown function of the file user/editLog.php. Such manipulation of the argument sid/addti…

▾ Sunlitningzichun · student-management-systemEPSS 0.31%via NVD
CVE-2026-97646High· 7.3PoC
2d ago

A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This affects an unknown function of the file admin/fun/getStudent.php. This manipulation of the argument sid causes au…

▾ Midnightningzichun · student-management-systemEPSS 0.30%via NVD
CVE-2026-97636Medium· 6.5
3d ago

Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key

Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path…

▾ SunlitApache Software Foundation · apache-airflow-providers-hashicorpEPSS 0.21%via NVD
CVE-2026-97368Medium· 6.3PoC
3d ago

A weakness has been identified in chillzhuang SpringBlade up to 5.0.2

A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/java/org/springblade/system/service/impl/UserServiceImpl.java of th…

▾ Twilightchillzhuang · SpringBladeEPSS 0.23%via NVD
CVE-2026-77293High· 7.1PoC
3d ago

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against the attacker-controlled tripId but deleteNoteFile in server/src/se…

▾ Midnightmauriceboe · TREKEPSS 0.38%via NVD
CVE-2026-48073Medium· 4.3
3d ago

Docmost is open-source collaborative wiki and documentation software

Docmost is open-source collaborative wiki and documentation software. From 0.70.0 until 0.80.1, a low-privileged authenticated user who can edit an exportable page can embed a forged attachmentId that belongs to a restricted page in the …

▾ Sunlitdocmost · docmostEPSS 0.19%via NVD
CVE-2026-52850Medium· 4.3
3d ago

Docmost is open-source collaborative wiki and documentation software

Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member who does not belong to a private space can call the transclusion / sync-block lookup API with a known sourcePageId a…

▾ Sunlitdocmost · docmostEPSS 0.19%via NVD
CVE-2026-79759Medium· 4.3
3d ago

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0 until 2.5.1, the POST /credentials/:id/deploy-to-host endpoint resolves credential and target-host records from atta…

▾ SunlitTermix-SSH · TermixEPSS 0.27%via NVD
CVE-2026-79758Medium· 5.4PoC
3d ago

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0 until 2.5.1, authenticated Termix users can access the server-stats API without per-host authorization. GET /status …

▾ TwilightTermix-SSH · TermixEPSS 0.43%via NVD
CVE-2026-76907Medium· 6.5
3d ago

LaSuite Doc is a collaborative note taking, wiki and documentation platform

LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 4.8.2 until 5.4.0, GET /api/v1.0/documents/search/ accepts sequential seven-digit document paths to scope descendant searches without requiring the caller …

▾ Sunlitsuitenumerique · docsEPSS 0.25%via NVD
CVE-2026-78310Medium· 4.3
3d ago

Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

▾ SunlitDeltaww · DIAEnergieEPSS 0.21%via NVD
CVE-2026-87739Medium· 6.9
3d ago

An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation

An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and …

▾ SunlitPaperCut · PaperCut NG/MFEPSS 0.38%via NVD
CVE-2026-93661Low· 2.7
3d ago

The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any …

The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any …

▾ SunlitEPSS 0.17%via NVD
CVE-2026-89004Low· 2.7
3d ago

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the c…

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the c…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-82849Medium· 4.3
3d ago

The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another use…

The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another use…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-96762High· 7.3
3d ago

A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1

A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypa…

▾ Twilightkvcache-ai · mooncakeEPSS 0.29%via NVD
CVE-2026-84720Medium· 6.5
4d ago

A flaw was found in the Ansible Automation Platform automation-controller

A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between workflow nodes, is not wrapped in preve…

▾ SunlitRed Hat · automation-controllerEPSS 0.27%via NVD
CVE-2026-84713Medium· 6.5
4d ago

A flaw was found in the automation-controller notification subsystem

A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notification_ configuration is protected from API filtering, its recipient value is…

▾ SunlitRed Hat · ansible-automation-platform-27/controller-rhel9EPSS 0.31%via NVD
CVE-2026-66076Low· 2.3PoC⚖ disputed
4d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, is_authorized/2 calls rabbit_mgmt_util:is_authorized/2, which checks only the management tag, instead of is_authorized_vhost/2. Th…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.27%via NVD
CVE-2026-90899High· 8.2
4d ago

Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest checkout records solely by supplying an email …

Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest checkout records solely by supplying an email …

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.33%via NVD
CVE-2026-76089High· 7.7
4d ago

Formie is a Craft CMS plugin for creating forms

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-s…

▾ Twilightverbb · formieEPSS 0.24%via NVD
CVE-2026-76087High· 8.2
4d ago

Formie is a Craft CMS plugin for creating forms

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's anonymous formie/submissions/submit action in SubmissionsController::actionSubmit trusts a client-supplied submissionId when loading an incomplete subm…

▾ Twilightverbb · formieEPSS 0.31%via NVD
CVE-2026-93513Medium· 4.3
4d ago

Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.

Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.

▾ SunlitSiteSkite · siteskiteEPSS 0.18%via NVD
CVE-2026-93623Medium· 5.3
4d ago

Unauthenticated Insecure Direct Object References (IDOR) in AI Engine <= 3.7.8 versions.

Unauthenticated Insecure Direct Object References (IDOR) in AI Engine <= 3.7.8 versions.

▾ SunlitJordy Meow · ai-engineEPSS 0.23%via NVD
CVE-2026-95592Medium· 5.3
4d ago

Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.

Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.

▾ SunlitOleh RadiusTheme · tlp-teamEPSS 0.24%via NVD
CVE-2026-95602Medium· 6.5
4d ago

Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Request A Quote: from n…

Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Request A Quote: from n…

▾ SunlitYITH · YITH WooCommerce Request A QuoteEPSS 0.28%via NVD
CVE-2026-86867Medium· 6.5
4d ago

Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls

Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls. There are four handler methods in `libs/ktem/ktem/pag…

▾ SunlitCinnamon AI · KotaemonEPSS 0.18%via NVD
CWE-639 vulnerabilities (CVEs) — page 2 · VulnSea