Vulnerability index

Browse CVEs

7 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Mycomplianceoffice MEDIUM 6.5
CVE-2026-53909

MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side checks, which can be bypasse…

Mitigation only
Fix from $1,600 2026-07-01
Mycomplianceoffice HIGH 8.2
CVE-2026-53906

MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload. Improper validation of the …

Mitigation only
Fix from $1,950 2026-07-01
Mycomplianceoffice HIGH 8.1
CVE-2026-53903

MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/trading-document/fetchPdfStatement …

Mitigation only
Fix from $1,950 2026-07-01
Mco HIGH 7.1
CVE-2026-53904

MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each password reset request invalidate…

Mitigation only
Fix from $1,950 2026-07-01
Mycomplianceoffice HIGH 7.1
CVE-2026-53905

MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint. An authe…

Mitigation only
Fix from $1,950 2026-07-01
Mycomplianceoffice MEDIUM 6.5
CVE-2026-53902

MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated u…

Mitigation only
Fix from $1,600 2026-07-01
Mycomplianceoffice MEDIUM 5.4
CVE-2026-53907

MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with the ability to change the appl…

Mitigation only
Fix from $1,600 2026-07-01