Search Results (10705 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-108884 1 Jeecg 1 Jeecg Boot 2026-10-11 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageTemplateController delete handler that allows any authenticated user to delete message templates. Low-privileged attackers can obtain template ids from the unguarded list endpoint and delete shipped notification templates, causing system notices and workflow reminders to fail.
CVE-2026-108883 1 Jeecg 1 Jeecg Boot 2026-10-11 6.5 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the editThirdAppConfig handler that allows any authenticated user to modify third-party application configurations. Low-privileged attackers can replace client id, client secret, agent id and corp id of DingTalk, WeCom or Feishu integrations to redirect directory synchronisation and messaging to attacker-controlled applications or break them.
CVE-2026-108882 1 Jeecg 1 Jeecg Boot 2026-10-11 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController removeUserPosition handler that allows any authenticated user to remove position members. Low-privileged attackers can send DELETE requests with arbitrary userIds and positionId values to delete sys_user_position rows, detaching users from positions without logging.
CVE-2026-108878 1 Jeecg 1 Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragAppController queryById handler that allows low-privileged authenticated users to read any AI application configuration. Attackers can enumerate application ids via the unguarded /airag/app/listDict endpoint and query each id to obtain system prompts, memory prompts, model ids, knowledge base ids, and plugin bindings of other users' applications.
CVE-2026-108876 1 Jeecg 1 Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the putCancelQuit handler of SysUserController, allowing any authenticated user to cancel user resignations. Low-privileged attackers can supply user ids and a tenantId parameter or X-Tenant-Id header to restore ended, pending, or refused tenant memberships to normal.
CVE-2026-108875 1 Jeecg 1 Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController addSysUserGroup handler that allows any authenticated user to modify user group membership. Low-privileged attackers can send POST requests with arbitrary user ids and a groupId to add any users to administrator-maintained groups without permission checks.
CVE-2026-108874 1 Jeecg 1 Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to assign or remove department heads by calling PUT /sys/user/changeDepartChargePerson. Low-privileged attackers can supply arbitrary userId, department id, and status values to make any user a department head, widening department-scoped views, or demote existing heads.
CVE-2026-108868 1 Jeecg 1 Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to publish templated system announcements via POST /sys/api/sendBusTemplateAnnouncement. Low-privileged attackers can supply templateCode, toUser, and a forged fromUser to send notifications to arbitrary users through WebSocket, DingTalk, WeCom, Feishu and UniPush channels.
CVE-2026-108867 1 Jeecg 1 Jeecg Boot 2026-10-11 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SystemApiController getUserRoleSetById handler that allows any authenticated user to read other users' role assignments. Low-privileged attackers can supply an arbitrary userId parameter to retrieve assigned role codes and identify administrator accounts without the system:user:queryUserRole permission.
CVE-2026-108734 1 Frappe 1 Crm 2026-10-11 4.3 Medium
Frappe CRM 1.49.0 through 1.87.0 contains a missing authorization vulnerability in crm.api.doc.get_linked_docs_of_document that allows authenticated users to read linked documents without permission checks. Attackers can name a lead, deal, comment or user they cannot read to obtain linked call log phone numbers, deal organizations and mention notification text.
CVE-2026-108710 1 Orneryd 1 Nornicdb 2026-10-11 6.5 Medium
NornicDB through 1.4.1 contains a missing authorization vulnerability that allows authenticated users to bypass per-database read restrictions on the /nornicdb/search and /nornicdb/similar endpoints. Viewer-role users allowlisted for a database but denied read can submit search queries or node IDs to retrieve node IDs, labels and full property maps.
CVE-2026-108855 2026-10-11 5.4 Medium
UnicomAI Wanwu through 0.6.5 contains a missing authorization vulnerability that allows any authenticated enabled user to revoke other users' AppKeys for arbitrary apps via the unpublish endpoint. Attackers can supply a target appId and appType from the exploration marketplace to delete other users' api_key rows across organizations, cutting off MCP and OpenAPI client access.
CVE-2026-108851 1 Phpmyfaq 1 Phpmyfaq 2026-10-11 3.3 Low
phpMyFAQ through 4.1.10 contains a missing authorization vulnerability in the MCP server faq_search tool that allows MCP clients to read restricted FAQs because Search::searchDatabase() never applies user or group permission checks. Attackers connected to the phpmyfaq:mcp:server can issue search queries to retrieve the full question and answer text of active FAQs restricted to specific users or groups.
CVE-2026-108697 1 Coreshop 1 Coreshop 2026-10-11 4.3 Medium
CoreShop through 2026.2.2 contains a missing authorization vulnerability that allows low-privileged backend users to list permission-restricted resources because ResourceController listAction skips the isGrantedOr403() check. Authenticated Pimcore users lacking resource permissions can request the generated list routes to enumerate payment providers, carriers, price rules, stores, and tax rules including ids, names, and identifiers.
CVE-2026-96334 2026-10-11 5.6 Medium
Missing Authorization vulnerability in ThemeGrill User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through 5.2.7.
CVE-2026-95597 2026-10-11 6.5 Medium
Missing Authorization vulnerability in codemstory 워드프레스 결제 심플페이 pgall-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 워드프레스 결제 심플페이: from n/a through 5.5.17.
CVE-2026-93950 2026-10-11 7.5 High
Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108.
CVE-2026-65459 2026-10-11 7.5 High
Unauthenticated Arbitrary Content Deletion in Forminator <= 1.57.3 versions.
CVE-2026-62118 2026-10-11 7.3 High
Unauthenticated Broken Access Control in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.
CVE-2026-62035 2026-10-11 6.3 Medium
Subscriber Broken Access Control in AWS S3 for WordPress Plugin – Upcasted <= 3.1.0 versions.