| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any authenticated Home Assistant user because the backend did not consistently enforce the panel's admin-only authorization boundary. Affected surfaces included the backend API, upload API, stream routes, terminal WebSocket, Blueprint Studio WebSocket subscriptions, call_service, render_template, global_replace, file and stream access paths, upload handling, and terminal helpers. A non-admin user could invoke arbitrary Home Assistant services, expose Home Assistant state through templates, modify configuration files, access streamed or downloaded configuration content, upload files, or reach terminal-related helpers. These actions could compromise the confidentiality, integrity, and availability of the Home Assistant installation. This issue is fixed in version 2.5.2. |
| Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to version 12.1.3, the display_map parser function in the Leaflet service accepts attacker-controlled HTML in the overlays parameter, and resources/leaflet/jquery.leaflet.js uses the overlay name as a Leaflet layer-control label without escaping it. A wiki user with the edit permission can store malicious wikitext that causes script execution when another user previews or views the affected map. The script executes in the viewing user's browser session and can access data or perform actions available to that user. This issue is fixed in version 12.1.3. |
| An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges. |
| Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions. |
| Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. |
| Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. |
| Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions. |
| Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. |
| Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions. |
| Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. |
| Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. |
| Subscriber Broken Access Control in Homlisti <= 3.1.2 versions. |
| Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. |
| Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. |
| Unauthenticated Broken Access Control in Koji <= 2.2.1 versions. |
| Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects New User Approve: from n/a through 3.2.8. |
| A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. |
| A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
| The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch. |
| Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.20, a community moderator can feature or unfeature posts in other communities through federated CollectionAdd and CollectionRemove activities using CollectionType::Featured. After verify_mod_action authorizes the actor against self.community(), the receive handlers in crates/apub/activities/src/community/collection_add.rs and crates/apub/activities/src/community/collection_remove.rs dereference self.object as an ApubPost and update featured_community without verifying that post.community_id equals community.id. A moderator can therefore target an unrelated post owned by another community, push it into featured feeds and listings, or undo another community's legitimate curation decision. This issue is fixed in versions 0.19.19 and 1.0.0-alpha.20. |