| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2. |
| A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to override a more specific literal-mapped permission when both match. In the CA's profile-management REST API this allows a request to POST /v2/profiles/raw -- intended to require Administrator-level profiles.create permission -- to instead be authorized under the lower-privileged profiles.approve permission held by the default Certificate Manager Agents group. The highest threat from this vulnerability is to confidentiality and integrity of the certificate authority's issuance policy. |
| Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MultiVendorX: from n/a through 5.0.19. |
| Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions. |
| Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions. |
| Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions. |
| Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions. |
| Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions. |
| Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions. |
| Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions. |
| Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions. |
| Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions. |
| Unauthenticated Broken Access Control in Bookly <= 28.2 versions. |
| Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions. |
| Subscriber Broken Access Control in FormGent <= 1.12.2 versions. |
| Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions. |
| Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions. |
| Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts. |
| SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the Electron main process (app/electron/main.js). The handler ignores event.sender and forwards any received payload to every BrowserWindow returned by BrowserWindow.getAllWindows(), including windows belonging to other opened workspaces. A renderer connected to an attacker-controlled remote kernel can therefore send {cmd: "lockscreenByMode"} and have it delivered across the workspace boundary; a sibling workspace window whose lockScreenMode is set to 1 invokes lockScreen(). Repeated messages allow the remote workspace to repeatedly lock unrelated local workspace windows, causing a limited denial of service. No confidentiality, integrity, or code-execution impact was observed. |
| Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing authenticated app/org admins to grant channel permissions to non-member users. Attackers with admin privileges can insert override rows with arbitrary external user UUIDs to grant channel-scoped permissions such as channel.promote_bundle to users outside the organization. |