| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Contributor Broken Access Control in Style Kits <= 2.6.5 versions. |
| Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion. |
| Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. |
| Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions. |
| Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions. |
| Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. |
| Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. |
| Subscriber Broken Access Control in ListingPro <= 2.9.10 versions. |
| Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions. |
| Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions. |
| The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL runs and authorizes the caller on only the admin.login permission (the baseline permission held by every panel user). This allows any user with admin.login to mint a persistent API key bound to any account, and the forged key inherits the target account's API permissions. On installs where an API-enabled account holds broader permissions, this enables account impersonation and privilege escalation up to account takeover. |
| The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data. |
| A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in
unconfined context
This issue affects policycoreutils through 3.10. |
| Unauthenticated Broken Access Control in Civi <= 2.2.4 versions. |
| Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. |
| Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions. |
| This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check. |
| Contributor Broken Access Control in uListing <= 2.2.0 versions. |
| Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions. |