Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticat…
The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the p…
The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. Th…
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions,…
The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the …
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trust…
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged auth…
CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows aut…
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users w…
Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.
Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.