Vulnerabilities (CVE)

Filtered by CWE-862
Total 9902 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-63092 2026-07-23 N/A 4.3 MEDIUM
kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintext commercial license key by sending a GET request to the modules/activate dialog endpoint. The plugin's activate dialog handler in lib/areas.php returns the complete key via ModulesLicense::readKey() without performing an administrator check, as the dialog is gated only by the access.system permission which defaults to true for all non-admin roles, enabling attackers to use the disclosed key to activate the plugin on arbitrary third-party installations.
CVE-2026-11876 2026-07-23 N/A 5.0 MEDIUM
In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper RBAC authorization checks, allowing any authenticated user to enumerate all deployed stacks across all users and tenants. This includes stack component details, service connector information, and user IDs of stack owners. The vulnerability arises from two issues: missing endpoint-level RBAC checks and the use of a server-side `Client()` that bypasses the RBAC enforcement layer by directly accessing the database through `SqlZenStore`. This exposes sensitive information such as infrastructure topology, service connector details, stack ownership, and deployment metadata, potentially enabling cross-tenant reconnaissance and further attacks in multi-tenant ZenML Pro/Cloud deployments.
CVE-2026-55518 2026-07-23 N/A 9.6 CRITICAL
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the UI and GET /resources/:resource/:id/:related/new path, but the actual write endpoint, POST /resources/:resource/:id/:related, does not run the same authorization check before mutating the association through Avo::AssociationsController#create. An authenticated low-privileged Avo user can bypass hidden or disabled attach controls and directly attach related records to a parent record by sending a crafted POST request, which can lead to privilege escalation and cross-tenant data exposure where associations represent authorization-bearing relationships. This issue is fixed in versions 3.32.1 and 4.0.0.beta.51.
CVE-2026-65537 2026-07-23 N/A 4.3 MEDIUM
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
CVE-2026-65531 2026-07-23 N/A 4.8 MEDIUM
Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
CVE-2026-65525 2026-07-23 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
CVE-2026-65506 2026-07-23 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.
CVE-2026-65491 2026-07-23 N/A 4.3 MEDIUM
Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
CVE-2026-65486 2026-07-23 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
CVE-2026-65485 2026-07-23 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
CVE-2026-65479 2026-07-23 N/A 5.4 MEDIUM
Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
CVE-2026-59547 2026-07-23 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.
CVE-2026-59522 2026-07-23 N/A 6.5 MEDIUM
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
CVE-2026-57830 1 Ollyo 1 Helix Ultimate 2026-07-23 N/A 9.1 CRITICAL
Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.
CVE-2026-57808 2026-07-23 N/A 6.5 MEDIUM
Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.
CVE-2026-57717 2026-07-23 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.
CVE-2026-27422 2026-07-23 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.
CVE-2026-27418 2026-07-23 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
CVE-2026-27399 2026-07-23 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.
CVE-2026-27377 2026-07-23 N/A 6.7 MEDIUM
Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.