Skip to main content

CWE archive

CWE-915 CVEs

Programmatic archive

146 CVEs tagged with CWE-91525 Critical, 70 High, 44 Medium, 7 Low, 0 Unrated.

CVE-2026-72655

Published Aug 13, 2026

Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorize…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-71473

Published Aug 12, 2026

A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject…

CVSS 8.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-17095

Published Aug 12, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe reflection.

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-72778

Published Aug 11, 2026

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search c…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-18617

Published Aug 10, 2026

A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the i…

CVSS 8.8 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-72719

Published Aug 10, 2026

Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transfer Portals, Automation Rules, Macros, and Twilio Channels t…

CVSS 6.7 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-17598

Published Aug 7, 2026

Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administr…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-69258

Published Aug 4, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overr…

CVSS 8.8 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-12436

Published Jul 29, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have…

CVSS 8.4 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-63428

Published Jul 20, 2026

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id, name, value}]` array from the submitter and stores it verb…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-63102

Published Jul 20, 2026

rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-56679

Published Jul 15, 2026

9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body to persistent settings without a field whitelist, allowing a…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59888

Published Jul 14, 2026

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-58477

Published Jul 14, 2026

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration se…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-55810

Published Jul 10, 2026

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Gra…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55804

Published Jul 10, 2026

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55803

Published Jul 10, 2026

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-15083

Published Jul 10, 2026

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13244

Published Jul 10, 2026

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injection. This issue affects Tealiu…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12535

Published Jul 10, 2026

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9726

Published Jul 10, 2026

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affe…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-59721

Published Jul 9, 2026

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts an attacker-controlled MAILER…

CVSS 7.2 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-54601

Published Jul 7, 2026

FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT allows an authenticated tenant user to call POST /api/core/dataset/collection/cr…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-43925

Published Jul 6, 2026

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in the client self-registration e…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 146 CVEsPage 1 of 6