<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Security Misconfiguration</title>
  <link>https://cvedaily.com/pages/tags/misconfiguration.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/misconfiguration.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Security Misconfiguration</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:33 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-10616 – A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10616</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10616</strong></p>
  <p>A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function TeamTasksTool.executeComplete of the file internal/tools/team_tasks_lifecycle.go of the component Team Task Completion Handler. Executing a manipulation can lead to missing authorization. The attack may be launched remotely. The exploit has been made available to the public and could be us…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40715 – Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Acc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40715</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40715</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40715</strong></p>
  <p>Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40715">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40713 – Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Acc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40713</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40713</strong></p>
  <p>Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information exposure.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9590 – Improper access control in the permission validation component in Devolutions Se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9590</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9590</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9590</strong></p>
  <p>Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9590">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9522 – Improper access control in the PAM account discovery feature in Devolutions Serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9522</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9522</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9522</strong></p>
  <p>Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network discovery scan configurations.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9522">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45080 – Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45080</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45080</strong></p>
  <p>Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access control allows disclosure of password hash. This issue has been patched in version 2.10.4.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7198 – CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.862...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7198</guid>
    <pubDate>Tue, 02 Jun 2026 14:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7198</strong></p>
  <p>CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, and availability of affected installations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49782 – Missing Authorization vulnerability in Elementor Elementor Website Builder allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49782</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49782</strong></p>
  <p>Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Elementor Website Builder: from n/a through 4.1.0.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27351 – Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploitin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27351</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27351</strong></p>
  <p>Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Crew HRM: from n/a through 1.2.2.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42670 – Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42670</guid>
    <pubDate>Tue, 02 Jun 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42670</strong></p>
  <p>Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Five Star Restaurant Reservations: from n/a through 2.7.14.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42669 – Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42669</guid>
    <pubDate>Tue, 02 Jun 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42669</strong></p>
  <p>Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects EventPrime: from n/a through 4.3.2.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53346 – Missing Authorization vulnerability in ThimPress Thim Core allows Exploiting Inc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53346</guid>
    <pubDate>Tue, 02 Jun 2026 10:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53346</strong></p>
  <p>Missing Authorization vulnerability in ThimPress Thim Core allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Thim Core: from n/a through 2.3.3.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53345 – Missing Authorization vulnerability leading to code execution after installing m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53345</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53345</guid>
    <pubDate>Tue, 02 Jun 2026 10:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53345</strong></p>
  <p>Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress Thim Core.  This issue affects Thim Core: from n/a through 2.3.3.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53345">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53302 – Missing Authorization vulnerability in Anton Shevchuk Constructor allows Accessi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53302</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53302</guid>
    <pubDate>Tue, 02 Jun 2026 10:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53302</strong></p>
  <p>Missing Authorization vulnerability in Anton Shevchuk Constructor allows Accessing Functionality Not Properly Constrained by ACLs.  This issue affects Constructor: from n/a through 1.6.5.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53302">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-52766 – Missing Authorization vulnerability in Printeers Printeers Print &amp; Ship allows E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52766</guid>
    <pubDate>Tue, 02 Jun 2026 10:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-52766</strong></p>
  <p>Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Printeers Print & Ship: from n/a through 1.17.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9234 – The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9234</guid>
    <pubDate>Tue, 02 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9234</strong></p>
  <p>The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing capability checks and nonce verification on the admin_post_settings_save_woo-jtl-connector action (handled by JtlConnectorAdmin::save()) and on the wp_ajax_downloadJTLLogs and wp_ajax_clearJTLLogs AJAX actions (handled by the global download…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9614 – An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9614</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9614</strong></p>
  <p>An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45281 – Nextcloud is an open source content collaboration platform. In Nextcloud Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45281</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45281</strong></p>
  <p>Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, with the knowledge of other users’ principal URL an attacker could possibly send a request to gain full access to their calendar. Therefore, the attacker must be an authenticated user. This is because of improper authorization controls in the backend…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10277 – A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c26633257...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10277</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10277</strong></p>
  <p>A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affects the function saveToDisk of the file src/tools/gmail.ts of the component MCP Gmail Tool. Performing a manipulation results in improper access controls. It is possible to initiate the attack remotely. The exploit has been made public and could be used. This product is using a ro…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8501 – Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8501</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8501</strong></p>
  <p>Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to perform sensitive and privileged operations on the target system.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-782</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42677 – Missing Authorization vulnerability in Ben Balter WP Document Revisions allows E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42677</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42677</strong></p>
  <p>Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects WP Document Revisions: from n/a before 4.0.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42675 – Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42675</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42675</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42675</strong></p>
  <p>Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Hydra Booking: from n/a through 1.1.41.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42675">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42671 – Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Inco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42671</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42671</strong></p>
  <p>Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects GeoDirectory: from n/a through 2.8.157.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42682 – Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42682</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42682</strong></p>
  <p>Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects wpForo Forum: from n/a through 3.0.6.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10255 – A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory Sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10255</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10255</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10255</strong></p>
  <p>A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_statement of the file application/controllers/ShowForm.php. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10255">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40547 – SOPlanning is vulnerable to Path Traversal in backup endpoints.  Authenticated r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40547</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40547</strong></p>
  <p>SOPlanning is vulnerable to Path Traversal in backup endpoints.  Authenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow reading and executing files previously added through the backup functionality. Critically, due to CVE-2026-40543 (Missing Authorization), any backup file can be read by any (unauthorized) user.  This issue affects SOPlanning vers…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10152 – A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10152</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10152</guid>
    <pubDate>Sat, 30 May 2026 20:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10152</strong></p>
  <p>A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This issue affects some unknown processing of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation results in improper access controls. The attack may be launched remotely. The exploit is now public and may be used. The project was informed of the…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10152">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49386 – In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49386</guid>
    <pubDate>Fri, 29 May 2026 19:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49386</strong></p>
  <p>In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49385 – In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49385</guid>
    <pubDate>Fri, 29 May 2026 19:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49385</strong></p>
  <p>In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49198 – Improper access control in the MQTT broker allows wildcard topic subscriptions, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49198</guid>
    <pubDate>Fri, 29 May 2026 09:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49198</strong></p>
  <p>Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorized actors.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10056 – CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10056</guid>
    <pubDate>Fri, 29 May 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10056</strong></p>
  <p>CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote attacker to steal the session token of an authenticated user and perform Administrator Account Takeover via a malicious cross-origin web page visited by the victim. The High security mode is not affect…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-942</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44884 – Portainer Community Edition is a lightweight service delivery platform for conta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44884</guid>
    <pubDate>Thu, 28 May 2026 22:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44884</strong></p>
  <p>Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8 and 2.39.1, a missing authorization vulnerability in the Custom Template file endpoint (GET /api/custom_templates/{id}/file) allows any authenticated user to read the file content of any custom…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42071 – Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42071</guid>
    <pubDate>Thu, 28 May 2026 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42071</strong></p>
  <p>Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2.28.1, a missing authorization check in MantisBT's file visibility function allows any authenticated user (REPORTER+) to download attachments on private bugnotes they should not be able to access, via the REST API endpoint GET /api/rest/issues/{id}/files and SOAP API mc_issue_attachment_get endpoint. This vulnerability…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8689 – The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8689</guid>
    <pubDate>Thu, 28 May 2026 09:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8689</strong></p>
  <p>The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.11.14. This is due to a missing capability check on the renderChartPages() and uploadData() functions, where the wp_ajax_visualizer-create-chart and wp_ajax_visualizer-edit-chart AJAX actions invoke renderChartPages() without any current_user_…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6937 – The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6937</guid>
    <pubDate>Thu, 28 May 2026 09:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6937</strong></p>
  <p>The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.11.8 due to the plugin not properly verifying that a user is authorized to perform an action via the bulk appointments REST API endpoint. This makes it possible for unauthenticated attackers to modify arbitrary appoint…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49054 – Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Explo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49054</guid>
    <pubDate>Wed, 27 May 2026 17:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49054</strong></p>
  <p>Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects The Post Grid: from n/a through 7.9.2.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-41656 – Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41656</guid>
    <pubDate>Wed, 27 May 2026 17:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-41656</strong></p>
  <p>Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Account Manager for WooCommerce: from n/a through 2.1.2.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49053 – Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49053</guid>
    <pubDate>Wed, 27 May 2026 15:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49053</strong></p>
  <p>Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49052 – Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49052</guid>
    <pubDate>Wed, 27 May 2026 15:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49052</strong></p>
  <p>Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49051 – Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49051</guid>
    <pubDate>Wed, 27 May 2026 15:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49051</strong></p>
  <p>Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects WP Meta and Date Remover: from n/a through 2.3.6.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49047 – Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49047</guid>
    <pubDate>Wed, 27 May 2026 15:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49047</strong></p>
  <p>Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects DearFlip: from n/a through 2.4.27.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49045 – Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Inc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49045</guid>
    <pubDate>Wed, 27 May 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49045</strong></p>
  <p>Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Adminimize: from n/a through 1.11.11.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48973 – Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48973</guid>
    <pubDate>Wed, 27 May 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48973</strong></p>
  <p>Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects SVG Support: from n/a through 2.5.14.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31266 – Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31266</guid>
    <pubDate>Wed, 27 May 2026 15:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31266</strong></p>
  <p>Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48971 – Missing Authorization vulnerability in WebToffee Product Import Export for WooCo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48971</guid>
    <pubDate>Wed, 27 May 2026 14:17:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48971</strong></p>
  <p>Missing Authorization vulnerability in WebToffee Product Import Export for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Product Import Export for WooCommerce: from n/a through 2.5.6.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42753 – Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42753</guid>
    <pubDate>Wed, 27 May 2026 11:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42753</strong></p>
  <p>Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCFM Membership: from n/a through <= 2.11.10.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42726 – Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42726</guid>
    <pubDate>Wed, 27 May 2026 11:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42726</strong></p>
  <p>Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AWP Classifieds: from n/a through <= 4.4.5.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-47268 – Missing authorization vulnerability in AddOns functionality in Synology Surveill...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47268</guid>
    <pubDate>Wed, 27 May 2026 09:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47268</strong></p>
  <p>Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3897 – The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Sto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3897</guid>
    <pubDate>Wed, 27 May 2026 08:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3897</strong></p>
  <p>The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check user capabilities. This makes it possible for authenticated attackers with Subscriber-…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3896 – The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3896</guid>
    <pubDate>Wed, 27 May 2026 08:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3896</strong></p>
  <p>The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check user capabilities. This makes it possible for authenticated attackers with Subscriber-level a…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3895 – The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3895</guid>
    <pubDate>Wed, 27 May 2026 08:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3895</strong></p>
  <p>The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lvca_admin_ajax` AJAX action in all versions up to, and including, 3.9.4 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not check user capabilities. This makes it possible for authenticated attackers with Subsc…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9604 – A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9604</guid>
    <pubDate>Tue, 26 May 2026 23:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9604</strong></p>
  <p>A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improper access controls. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 3.9.2 is able to resolve this issue. The affected component should be upgraded.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9603 – A security vulnerability has been detected in SourceCodester eDoc Doctor Appoint...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9603</guid>
    <pubDate>Tue, 26 May 2026 22:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9603</strong></p>
  <p>A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument ID leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9581 – A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9581</guid>
    <pubDate>Tue, 26 May 2026 21:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9581</strong></p>
  <p>A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper access controls. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 3.9.2 is sufficient to resolve this issue. Upgrading the affected component is recommended.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9580 – A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9580</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9580</guid>
    <pubDate>Tue, 26 May 2026 21:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9580</strong></p>
  <p>A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.9.2 is sufficient to fix this issue. It is suggested to upgrade…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9580">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9579 – A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9579</guid>
    <pubDate>Tue, 26 May 2026 21:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9579</strong></p>
  <p>A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The manipulation of the argument userIdentity results in improper access controls. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 3.9.2 is recommended to address this issu…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48592 – Missing Authorization vulnerability in oban-bg oban_web ('Elixir.Oban.Web.Jobs.D...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48592</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48592</guid>
    <pubDate>Tue, 26 May 2026 21:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48592</strong></p>
  <p>Missing Authorization vulnerability in oban-bg oban_web ('Elixir.Oban.Web.Jobs.DetailComponent' modules) allows unauthorized job worker substitution.  The handle_event("save-job", ...) handler in 'Elixir.Oban.Web.Jobs.DetailComponent' does not perform an authorization check, unlike the sibling cancel, delete, and retry handlers which all verify the caller's privileges via can?/2. An authenticated…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48592">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14361 – Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14361</guid>
    <pubDate>Tue, 26 May 2026 21:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14361</strong></p>
  <p>Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly Constrained by ACLs.  This issue affects Woocommerce Envato Affiliates: from n/a through 1.2.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27331 – Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27331</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27331</guid>
    <pubDate>Tue, 26 May 2026 20:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27331</strong></p>
  <p>Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects WpTravelly: from n/a through 2.1.5.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27331">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25444 – Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25444</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25444</guid>
    <pubDate>Tue, 26 May 2026 20:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25444</strong></p>
  <p>Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects WpBookingly: from n/a through 1.2.9.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25444">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25426 – Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25426</guid>
    <pubDate>Tue, 26 May 2026 20:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25426</strong></p>
  <p>Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.1.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24520 – Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24520</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24520</guid>
    <pubDate>Tue, 26 May 2026 20:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24520</strong></p>
  <p>Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Tiktok Feed: from n/a through 1.0.24.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24520">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9562 – A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9562</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9562</guid>
    <pubDate>Tue, 26 May 2026 17:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9562</strong></p>
  <p>A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The affected element is an unknown function of the component Dashboard. Such manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensurin…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9562">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24638 – Missing Authorization vulnerability in Webful Creations RepairBuddy allows Explo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24638</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24638</guid>
    <pubDate>Tue, 26 May 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24638</strong></p>
  <p>Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects RepairBuddy: from n/a through 4.1121.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24638">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24590 – Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24590</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24590</guid>
    <pubDate>Tue, 26 May 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24590</strong></p>
  <p>Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Paid Videochat Turnkey Site: from n/a through 7.3.23.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24590">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39655 – Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39655</guid>
    <pubDate>Tue, 26 May 2026 08:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39655</strong></p>
  <p>Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Mayosis Core: from n/a through 5.4.7.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4795 – A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions thro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4795</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4795</guid>
    <pubDate>Tue, 26 May 2026 02:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4795</strong></p>
  <p>A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0,  GS1200-5HPv3 firmware versions through 1.00(ACPU.2)C0, GS1200-8HPv3 firmware versions through 1.00(ACPV.2)C0, and GS1200-10v3 firmware versions through 1.00(ACPW.2)C0 could allow a LAN-based, unauthenticated attacker to read the system configura…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4795">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9517 – A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9517</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9517</guid>
    <pubDate>Tue, 26 May 2026 00:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9517</strong></p>
  <p>A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the component Student Management Handler. Executing a manipulation can lead to improper access controls. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This product impleme…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9517">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45438 – Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45438</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45438</guid>
    <pubDate>Mon, 25 May 2026 23:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45438</strong></p>
  <p>Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Smart Coupons for WooCommerce: from n/a before 2.3.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45438">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45209 – Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45209</guid>
    <pubDate>Mon, 25 May 2026 23:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45209</strong></p>
  <p>Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects MyCryptoCheckout: from n/a through 2.161.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42776 – Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42776</guid>
    <pubDate>Mon, 25 May 2026 23:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42776</strong></p>
  <p>Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Sunshine Photo Cart: from n/a through 3.6.7.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42763 – Missing Authorization vulnerability in SePay team SePay Gateway allows Retrieve ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42763</guid>
    <pubDate>Mon, 25 May 2026 23:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42763</strong></p>
  <p>Missing Authorization vulnerability in SePay team SePay Gateway allows Retrieve Embedded Sensitive Data.  This issue affects SePay Gateway: from n/a through 1.1.20.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32389 – Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Inc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32389</guid>
    <pubDate>Mon, 25 May 2026 23:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32389</strong></p>
  <p>Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects NanoCare: from n/a before 1.2.2.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27398 – Missing Authorization vulnerability in WP Chill RSVP and Event Management allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27398</guid>
    <pubDate>Mon, 25 May 2026 22:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27398</strong></p>
  <p>Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects RSVP and Event Management: from n/a through 2.7.16.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27357 – Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27357</guid>
    <pubDate>Mon, 25 May 2026 22:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27357</strong></p>
  <p>Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects WP Search Analytics: from n/a before 1.5.0.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27346 – Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27346</guid>
    <pubDate>Mon, 25 May 2026 22:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27346</strong></p>
  <p>Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects B2BKing: from n/a before 5.2.10.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24592 – Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24592</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24592</guid>
    <pubDate>Mon, 25 May 2026 22:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24592</strong></p>
  <p>Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Auto Affiliate Links: from n/a through 6.8.8.3.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24592">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24586 – Missing Authorization vulnerability in Themeansar Newses allows Exploiting Incor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24586</guid>
    <pubDate>Mon, 25 May 2026 22:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24586</strong></p>
  <p>Missing Authorization vulnerability in Themeansar Newses allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Newses: from n/a through 2.0.0.77.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24582 – Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24582</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24582</guid>
    <pubDate>Mon, 25 May 2026 22:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24582</strong></p>
  <p>Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects FlexTable: from n/a through 3.24.0.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24582">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24527 – Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24527</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24527</guid>
    <pubDate>Mon, 25 May 2026 22:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24527</strong></p>
  <p>Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.14.0.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24527">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24545 – Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24545</guid>
    <pubDate>Mon, 25 May 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24545</strong></p>
  <p>Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects QR Redirector: from n/a through 2.0.3.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24546 – Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24546</guid>
    <pubDate>Mon, 25 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24546</strong></p>
  <p>Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects GamiPress: from n/a through 7.6.3.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9412 – A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9412</guid>
    <pubDate>Mon, 25 May 2026 02:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9412</strong></p>
  <p>A vulnerability was determined in SourceCodester Indian Invoicing System 1.0. Impacted is an unknown function of the component Backend Endpoint. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Multiple endpoints are affected.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9350 – A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9350</guid>
    <pubDate>Sun, 24 May 2026 04:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9350</strong></p>
  <p>A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This affects the function check_all_command_guards of the file tools/approval.py of the component Batch Runner. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respo…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9284 – The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthoriz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9284</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9284</strong></p>
  <p>The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` context without validating order o…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6895 – The WishList Member plugin for WordPress is vulnerable to Missing Authorization ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6895</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6895</strong></p>
  <p>The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing capability checks in the 'export_settings' function. This function returns the REST API Secret Key to the attacker in the AJAX JSON response. An attacker who obtains this key can auth…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6419 – The WishList Member plugin for WordPress is vulnerable to Privilege Escalation v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6419</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6419</strong></p>
  <p>The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check in the ajax_get_screen() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to supply an arbitrary admin screen identifier via the data[url] paramete…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9251 – Missing authorization in the entry status management feature in Devolutions Serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9251</guid>
    <pubDate>Fri, 22 May 2026 16:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9251</strong></p>
  <p>Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authenticated user to bypass the administrator-enforced Pending Approval flow and gain access to an entry's data via a crafted status change request.  This issue affects :    *  Devolutions Server 2026.1.6.0 through 2026.1.16.0   *  Devolutions Server 2025.3.20.0 and earlier</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9246 – Improper access control in the entry documentation and attachment features in De...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9246</guid>
    <pubDate>Fri, 22 May 2026 16:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9246</strong></p>
  <p>Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a crafted API request.  This issue affects :    *  Devolutions Server 2026.1.6.0 through 2026.1.16.0   *  Devolutions Server 2025.3.20.0 and earlier</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9224 – Missing authorization in the user profile update feature in Devolutions Server a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9224</guid>
    <pubDate>Fri, 22 May 2026 16:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9224</strong></p>
  <p>Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attributes via a crafted API request.  This issue affects :    *  Devolutions Server 2026.1.6.0 through 2026.1.16.0   *  Devolutions Server 2025.3.20.0 and earlier</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9223 – Missing authorization in the vault import feature in Devolutions Server  2026.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9223</guid>
    <pubDate>Fri, 22 May 2026 16:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9223</strong></p>
  <p>Missing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5171 – Improper access control in the entry activity log feature in Devolutions Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5171</guid>
    <pubDate>Fri, 22 May 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5171</strong></p>
  <p>Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request.  This issue affects :    *  Devolutions Server 2026.1.6.0 through 2026.1.16.0   *  Devolutions Server 2025.3.20.0 and earlier</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31231 – Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31231</guid>
    <pubDate>Fri, 22 May 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31231</strong></p>
  <p>Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to gaining read access to unauthorized data.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34908 – A malicious actor with access to the network could exploit an Improper Access Co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34908</guid>
    <pubDate>Fri, 22 May 2026 02:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34908</strong></p>
  <p>A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8350 – Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8350</guid>
    <pubDate>Thu, 21 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8350</strong></p>
  <p>Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative Group. Any authenticated user with access to the bulk user assignment dashboard page can add any user email to any group and can remove legitimate admins. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 7.5 with v…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39593 – Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39593</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39593</guid>
    <pubDate>Thu, 21 May 2026 18:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39593</strong></p>
  <p>Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects HAPPY: from n/a through 1.0.10.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39593">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27393 – Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exploiting I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27393</guid>
    <pubDate>Thu, 21 May 2026 09:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27393</strong></p>
  <p>Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects CF7 WOW Styler: from n/a through 1.7.6.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45443 – Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Dra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45443</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45443</guid>
    <pubDate>Wed, 20 May 2026 13:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45443</strong></p>
  <p>Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through 5.5.1.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45443">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42834 – Improper access control in Windows Admin Center allows an authorized attacker to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42834</guid>
    <pubDate>Wed, 20 May 2026 13:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42834</strong></p>
  <p>Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27424 – Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27424</guid>
    <pubDate>Wed, 20 May 2026 13:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27424</strong></p>
  <p>Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels.  This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.11.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27424">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
