Vulnerabilities (CVE)

Filtered by CWE-862
Total 9903 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-4843 2026-07-23 N/A 4.3 MEDIUM
The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the process_ajax_restore_action() function in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's Google Sheets API token and configuration options.
CVE-2026-8238 1 Concretecms 1 Concrete Cms 2026-07-23 N/A 5.3 MEDIUM
Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' endpoint returns the full content of any conversation message. An unauthenticated attacker can enumerate all conversation messages, including messages from restricted pages, member-only areas, and the moderation queue. File attachments with download URLs are also exposed. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Tristan Madani for reporting.
CVE-2026-45260 2026-07-23 N/A 8.1 HIGH
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE operation through /asset/webdav{path} without an authentication plugin in bundles/CoreBundle/src/Controller/WebDavController.php, and models/Asset/WebDAV/Tree.php performs asset mutation and deletion through models/Asset.php before checking a current Pimcore user or the rename, delete, create, or publish permissions, allowing unauthorized asset deletion, moves, or overwrites. This issue is fixed in versions 11.5.17 (LTS) and 12.3.7.
CVE-2026-47657 2026-07-23 N/A N/A
HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenticated user to trigger the removal of all members from any Space, regardless of their own role or membership in that Space. Versions 1.13.0 through 1.18.2 are affected. The vulnerability has been patched in version 1.18.3, and all users are encouraged to upgrade to this version or later immediately. No known workaround is available.
CVE-2026-57494 2026-07-23 N/A N/A
AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target agent name to `GET /api/agenticmail/tasks/pending?assignee=<name>`. The returned task objects include the task IDs and payloads. The same task IDs can then be used with the capability-style task mutation endpoints (`/tasks/:id/claim`, `/tasks/:id/result`, `/tasks/:id/complete`, `/tasks/:id/fail`) to claim, complete, or fail tasks assigned to a different agent. Because ordinary authenticated agents can discover agent names through `GET /api/agenticmail/accounts/directory`, the task ID effectively stops being a secret capability. This turns the intended capability model into a cross-agent authorization bypass. Version 0.9.64 contains a fix.
CVE-2026-44585 2026-07-23 N/A 5.4 MEDIUM
Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint accepts a user-supplied service identifier without enforcing ownership validation, allowing authenticated users to create support tickets referencing services belonging to other accounts by modifying the service ID in the request. An attacker could modify the service ID value in the client-side request and successfully create a ticket associated with another user's service. The vulnerability requires authentication and does not provide direct access to service contents or customer data. However, referenced service information could become visible to support personnel handling the ticket. Successful exploitation could allow an authenticated user to: create support tickets referencing services belonging to other users, potentially cause support staff to interact with or review unrelated customer services. The vulnerability did not allow direct access to another user's service, modification of another user's service or retrieval of confidential service data through the vulnerable endpoint itself. This issue has been fixed in version 1.5.0.
CVE-2026-59677 2026-07-23 N/A N/A
A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10.
CVE-2026-65055 2026-07-23 N/A 5.3 MEDIUM
Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal workflow configuration of any private project by supplying a project ID to the filters_data API endpoints on UserStory, Task, Issue, and Epic viewsets. Attackers can send unauthenticated GET requests to the filters_data endpoints with sequential integer project IDs to enumerate private project membership details including user IDs, full names, and gravatar hashes, bypassing the access controls that correctly restrict other project API endpoints.
CVE-2026-65011 2026-07-23 N/A 4.3 MEDIUM
Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. Attackers with the low-privilege eventdefinitions:create capability can read private event definitions including detection queries, aggregation thresholds, grouping fields, schedules, and notification bindings by duplicating them.
CVE-2026-64622 2026-07-23 N/A 7.5 HIGH
Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/secret) to the ApprovalInbox GET read routes, so even when an operator configures a secret, unauthenticated actors can access sensitive approval request details. The GET /approvals/?status=all, GET /approvals/:id, GET /approvals/stats, and GET /approvals/sse routes disclose full ApprovalEntry content including action/target shell-command strings, file paths, justifications, and risk levels. All responses also carry a hardcoded Access-Control-Allow-Origin: * header, enabling cross-origin disclosure from any website the operator visits. This is an incomplete fix for GHSA-mxjx-28vx-xjjj.
CVE-2026-65530 2026-07-23 N/A 4.3 MEDIUM
Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.
CVE-2026-65524 2026-07-23 N/A 4.3 MEDIUM
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
CVE-2026-65499 2026-07-23 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-65487 2026-07-23 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
CVE-2026-65484 2026-07-23 N/A 6.3 MEDIUM
Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
CVE-2026-65478 2026-07-23 N/A 5.4 MEDIUM
Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
CVE-2026-65472 2026-07-23 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
CVE-2026-65468 2026-07-23 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
CVE-2026-65453 2026-07-23 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
CVE-2026-65452 2026-07-23 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.