VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

668 CVEsRSS

CVE-2026-88910Medium· 5.3
1w ago

The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media files and their database records by iterating identifiers.

The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media files and their database records by iterating identifiers.

▾ SunlitEPSS 0.30%via NVD
CVE-2026-82125Medium· 5.3
1w ago

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderation status of a comment before returning its content, allowing unauthenticated users to read the content of comm…

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderation status of a comment before returning its content, allowing unauthenticated users to read the content of comm…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-89063High· 7.5PoC
1w ago

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation…

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation…

▾ Midnightladela · Online Scheduling and Appointment Booking System – BooklyEPSS 1.6%via NVD
CVE-2026-88065High· 7.5
1w ago

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/ph…

▾ TwilightNIAEFEUP · tts-beEPSS 0.51%via NVD
CVE-2026-18423High· 7.1⚖ disputed
1w ago

Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs

Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs . An authenticated user holding only view permission on a single Express entity could t…

▾ Twilightconcretecms · concrete_cmsEPSS 0.25%via NVD
CVE-2026-79409Medium· 6.5PoC
1w ago

An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.

An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-91933High· 7.1
1w ago

Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid

Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can i…

▾ TwilightFlowiseAI · FlowiseEPSS 0.35%via NVD
CVE-2026-91984Medium· 4.3
1w ago

Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project

Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into arbitrary other tenant project views via POST o…

▾ Sunlitgo-vikunja · vikunjaEPSS 0.26%via NVD
CVE-2026-91993Medium· 4.3PoC
1w ago

Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces

Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces. Attackers can submit repository identif…

▾ Twilightdromara · JpomEPSS 0.34%via NVD
CVE-2026-91846High· 7.1
1w ago

Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit explains that collection elements themselv…

Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit explains that collection elements themselv…

▾ TwilightMISP · MISPEPSS 0.35%via NVD
CVE-2026-89141Medium· 6.5
1w ago

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a u…

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a u…

▾ Sunlittigroumeow · AI Engine – The Chatbot, AI Framework & MCP for WordPressEPSS 0.45%via NVD
CVE-2026-90858High· 7.3PoC
1w ago

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affected by this vulnerability is the function session_start of the file adminappview.php. Executing a manipulation of …

▾ Midnightsubhajitkhan · online-clinic-management-systemEPSS 0.52%via NVD
CVE-2026-91773Medium· 4.3
1w ago

Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users to read lock metadata from repositories they cannot access

Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users to read lock metadata from repositories they cannot access. Attackers with write access to any repository can enumera…

▾ Sunlitcharmbracelet · soft-serveEPSS 0.34%via NVD
CVE-2026-91770Medium· 6.5PoC
1w ago

IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records

IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. Attackers can substitute arbitrary employee IDs in skill, education, cer…

▾ Twilightgamonoid · icehrmEPSS 0.45%via NVD
CVE-2026-54050Medium· 6.5PoC
1w ago

Sakai is a Collaboration and Learning Environment (CLE)

Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete another user's profile image because ProfileController.r…

▾ Twilightsakaiproject · sakaiEPSS 0.31%via NVD
CVE-2026-55178High· 7.5
1w ago

GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder

GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.2.3, multiple read and link endpoints authorize only the resource named in the request URL and fail to re-authorize a…

▾ Twilightgeolens-io · geolensEPSS 0.65%via NVD
CVE-2026-52820Medium· 5.3
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.57.0, PATCH /api/timesheets/{id} and POST /api/timesheets accept a user-controlled project identifier through TimesheetApiEditForm and FormTrait, and ProjectRepository::getQue…

▾ Sunlitkimai · kimaiEPSS 0.45%via NVD
CVE-2026-52821Medium· 5.3
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admin/project/create/{customer} require only the generic create_activity or create_project capability…

▾ Sunlitkimai · kimaiEPSS 0.43%via NVD
CVE-2026-52826Medium· 5.3
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/activity/{id}/rate/{rate} independently resolve the author…

▾ Sunlitkimai · kimaiEPSS 0.43%via NVD
CVE-2026-46498High· 7.6
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and OAuthAdapter accepts a…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.41%via NVD
CVE-2026-91144High· 7.5
1w ago

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the…

▾ Twilightzfile-dev · zfileEPSS 0.51%via NVD
CVE-2026-90697Medium· 4.3PoC
1w ago

A vulnerability was identified in SourceCodester Inventory Management System 1.0

A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file invoice.php. The manipulation of the argument ID leads to authorization bypass. It is possible to initiate the att…

▾ TwilightSourceCodester · Inventory Management SystemEPSS 0.41%via NVD
CVE-2026-9812Medium· 6.5
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating its value which allows an authenticated user with run prope…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating its value which allows an authenticated user with run prope…

▾ SunlitMattermost · MattermostEPSS 0.37%via NVD
CVE-2026-10542Medium· 5.0
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel action ownership which allows channel managers to update actions in other channels via the channel action update endpo…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel action ownership which allows channel managers to update actions in other channels via the channel action update endpo…

▾ SunlitMattermost · MattermostEPSS 0.13%via NVD
CVE-2026-82441Critical· 9.1
1w ago

Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs

Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs. Nimbus performed no validation of their contents on t…

▾ MidnightApache Software Foundation · org.apache.storm:storm-serverEPSS 0.27%via NVD
CVE-2026-54529Medium· 5.3
1w ago

SQLAdmin is a flexible Admin interface for SQLAlchemy models

SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.py accepts the attacker-controlled sortBy list-view query parameter without enforcing the configured column_sortable_l…

▾ Sunlitsmithyhq · sqladminEPSS 0.38%via NVD
CVE-2026-54178High· 8.1
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.12 and 7.0.35, HasUploadFields::uploadMultipleFilesToDi…

▾ TwilightLaravel-Backpack · CRUDEPSS 0.56%via NVD
CVE-2026-54180High· 7.6
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, the Update, Delete, and Reorder …

▾ TwilightLaravel-Backpack · CRUDEPSS 0.46%via NVD
CVE-2026-88912Medium· 4.2
2w ago

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, …

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, …

▾ SunlitEPSS 0.19%via NVD
CVE-2026-90521Medium· 6.3PoC
2w ago

A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132

A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipul…

▾ Twilightjaychouchannel · Tourism-Management-SystemEPSS 0.39%via NVD
CWE-639 vulnerabilities (CVEs) — page 7 · VulnSea