Total
2601 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-86111 | 2 Bookwyrm-social, Joinbookwyrm | 2 Bookwyrm, Bookwyrm | 2026-09-08 | 6.5 Medium |
| BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access the raw content of restricted statuses through the edit view, bypassing the privacy protections documented for these message types. | ||||
| CVE-2026-61688 | 1 Solidinvoice | 1 Solidinvoice | 2026-09-08 | 6.5 Medium |
| SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens within the same company by manipulating two writable Symfony UX LiveComponent props on the `DataGrid` component. Version 3.0.1 fixes the issue. | ||||
| CVE-2026-85607 | 1 Blinko | 1 Blinko | 2026-09-08 | 8.8 High |
| Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/routerTrpc/message.ts and conversation.clearMessages in server/routerTrpc/conversation.ts). Although these procedures require authentication, they query the database by caller-supplied conversation or message ID without verifying that the resource belongs to the requesting account. Any authenticated user can therefore read another user's full AI chat history, modify individual message content, and delete or wipe entire conversations by enumerating sequential integer IDs. | ||||
| CVE-2026-69375 | 1 Microsoft | 3 Exchange Server 2016, Exchange Server 2019, Exchange Server Se | 2026-09-08 | 6.5 Medium |
| Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. | ||||
| CVE-2026-86725 | 1 Wwbn | 1 Avideo | 2026-09-08 | 7.1 High |
| AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records. Attackers can supply arbitrary row IDs to overwrite another user's stored access_token and refresh_token, then delete the compromised record to destroy the victim's provider linkage. | ||||
| CVE-2026-86720 | 1 Wwbn | 1 Avideo | 2026-09-08 | 8.1 High |
| WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing authenticated users with canStream to access other users' restream destinations. Attackers can broadcast their live stream to victim-configured restream destinations by supplying arbitrary live_restreams_id values, hijacking YouTube, Facebook, or Twitch streams using victim stream keys. | ||||
| CVE-2026-86277 | 1 Sourcecodester | 1 Syllabus-aligned Learning Management Examination System | 2026-09-08 | 7.3 High |
| A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation of the argument ID leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2026-85594 | 1 Traefik | 1 Traefik | 2026-09-08 | N/A |
| Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend. | ||||
| CVE-2026-85579 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-09-08 | 4.3 Medium |
| SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs list from the global undo-log stack for a caller-supplied root ID without applying publish-access visibility filtering. An authenticated reader who knows the root ID of a visible document can obtain the internal root IDs of other documents (including private or unpublished ones) modified in the same cross-document transaction, disclosing internal identifiers and cross-document relationships. Document body contents are not directly exposed. | ||||
| CVE-2026-85381 | 1 Light0011 | 1 Cms | 2026-09-08 | 5.3 Medium |
| A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unknown processing of the file App/Home/Controller/ChapterController.class.php of the component Chapter Controller. Such manipulation of the argument content leads to authorization bypass. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-86261 | 1 Sfturing | 1 Hosp Order | 2026-09-08 | 7.3 High |
| A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Controller. Executing a manipulation of the argument userIdenf can lead to authorization bypass. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet. | ||||
| CVE-2026-86113 | 2 Bookwyrm-social, Joinbookwyrm | 2 Bookwyrm, Bookwyrm | 2026-09-08 | 6.5 Medium |
| BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading records. Attackers can exploit sequential ReadThrough IDs to overwrite arbitrary users' start dates, finish dates, progress, and progress mode, affecting reading statistics and exported data. | ||||
| CVE-2026-4945 | 2 Themeisle, Wordpress | 2 Otter Blocks – Gutenberg Blocks, Page Builder For Gutenberg Editor & Fse, Wordpress | 2026-09-08 | 5.3 Medium |
| The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.7 via the 'watch_checkout' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to pay for a lower-cost product while obtaining entitlement for a premium product by manipulating the product_id parameter independently of the price_id parameter in the Stripe checkout URL. | ||||
| CVE-2026-86489 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations | ||||
| CVE-2026-86488 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 6.5 Medium |
| In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches | ||||
| CVE-2026-86481 | 1 Jetbrains | 1 Youtrack | 2026-09-08 | 4.3 Medium |
| In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons | ||||
| CVE-2026-77995 | 1 Miniorange.com | 1 Miniorange Oauth Client Extension For Joomla | 2026-09-08 | N/A |
| Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes < 1.2.2 - The manipulation of a cookie value allows actors to login as arbitrary accounts, including admins. | ||||
| CVE-2026-85308 | 2 Brainstormforce, Wordpress | 2 Sureforms, Wordpress | 2026-09-07 | 5.3 Medium |
| Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through 2.12.5. | ||||
| CVE-2026-84769 | 2 Strategy11team, Wordpress | 2 Business Directory Plugin, Wordpress | 2026-09-07 | 6.5 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions. | ||||
| CVE-2026-85693 | 1 Mckaywrigley | 1 Chatbot-ui | 2026-09-07 | 6.5 Medium |
| Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other users by supplying arbitrary file UUIDs. The endpoint uses a service-role Supabase client that bypasses row-level security and fails to validate file ownership, enabling attackers to retrieve indexed content chunks from victim files through crafted POST requests. | ||||