In Docmost versions 0.70.0 through 0.70.2, restricted child pages hidden from public share viewers could still leak through public share search res...
The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion,...
Mattermost Plugins versions
Unauthenticated Insecure Direct Object References (IDOR) in GravityView
Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder
Subscriber Broken Access Control in WPComplete
Unauthenticated Broken Access Control in Booking and Rental Manager
Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP
Author Cross Site Scripting (XSS) in Hester Core
Affiliate Broken Access Control in Affiliates Manager
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.