7.5

CVSS3.1

CVE-2026-27449 - Umbraco.Engage.Forms Allows Unauthorized Access to Multiple API Endpoints

Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where certain API endpoints are exposed without enforcing authentication or authorization checks. The affected endpoints can be accessed directly over the ne…

📅 Published: Feb. 26, 2026, 9:51 p.m. 🔄 Last Modified: April 17, 2026, 2:15 p.m.

7.1

CVSS3.1

CVE-2026-25741 - Zulip Vulnerable to Modification of Payment Method (Stripe Default Card) by Non-Billing Users

Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card update session during an upgrade flow was accessible to users with only organization member privileges. When the associated Stripe Checkout session is comp…

📅 Published: Feb. 26, 2026, 9:44 p.m. 🔄 Last Modified: April 16, 2026, 4:15 p.m.

5.3

CVSS4.0

CVE-2026-3263 - go2ismail Asp.Net-Core-Inventory-Order-Management-System Security API improper authorization

A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functionality of the file /api/Security/ of the component Security API. Performing a manipulation results in improper authorization. Remote exploitati…

📅 Published: Feb. 26, 2026, 9:32 p.m. 🔄 Last Modified: April 17, 2026, 2:15 p.m.

1.2

CVSS4.0

CVE-2026-28227 - Discourse Vulnerable to Unauthorized Topic Creation in Staff-Only Categories via Topic Timer publis…

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users can publish topics into staff-only categories via the `publish_to_category` topic timer, bypassing authorization checks. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patch the issue. No kno…

📅 Published: Feb. 26, 2026, 9:27 p.m. 🔄 Last Modified: April 16, 2026, 4:15 p.m.

1.3

CVSS4.0

CVE-2026-28219 - Privilege Escalation via Mass Assignment Allows Regular Users to Set Topics as Global Banners

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an improper authorization check in the topic management logic allows authenticated users to modify privileged attributes of their topics. By manipulating specific parameters in a PUT or POST reques…

📅 Published: Feb. 26, 2026, 9:25 p.m. 🔄 Last Modified: April 16, 2026, 4:15 p.m.

5.3

CVSS4.0

CVE-2026-28218 - Discourse's Fail-Open Access Control in Data Explorer Plugin Allows Unauthorized SQL Query Execution

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, fail-open access control in Data Explorer plugin allows any authenticated user to execute SQL queries that have no explicit group assignments, including built-in system queries. Versions 2025.12.2,…

📅 Published: Feb. 26, 2026, 9:23 p.m. 🔄 Last Modified: April 16, 2026, 4:15 p.m.

1.3

CVSS4.0

CVE-2026-27154 - Discourse has XSS when editing a malicious post

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, a user full name can be evaluated as raw HTML when the following settings are set: `display_name_on_posts` => true; and `prioritize_username_in_ux` => false. Editing a post of a malicious user woul…

📅 Published: Feb. 26, 2026, 9:20 p.m. 🔄 Last Modified: April 17, 2026, 2:15 p.m.

1.3

CVSS4.0

CVE-2026-27153 - Discourse doesn't prevent moderators from exporting user Chat DMs

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, moderators could export user Chat DMs via the CSV export endpoint by exploiting an overly permissive allowlist in `can_export_entity?`. The method allowed moderators to export any entity not explic…

📅 Published: Feb. 26, 2026, 9:16 p.m. 🔄 Last Modified: April 17, 2026, 2:30 p.m.

5.3

CVSS4.0

CVE-2026-3262 - go2ismail Asp.Net-Core-Inventory-Order-Management-System Administrative redirect

A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component Administrative Interface. Such manipulation leads to execution after redirect. The attack may be launched remotely. The exploit has been disc…

📅 Published: Feb. 26, 2026, 9:02 p.m. 🔄 Last Modified: April 17, 2026, 2:30 p.m.

6.9

CVSS4.0

CVE-2026-3261 - itsourcecode School Management System Setting index.php sql injection

A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component Setting Handler. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and …

📅 Published: Feb. 26, 2026, 9:02 p.m. 🔄 Last Modified: April 17, 2026, 2:30 p.m.
Total resulsts: 349182
Page 1419 of 34,919
« previous page » next page
Filters