Skip to main content

CWE archive

CWE-915 CVEs

Programmatic archive

137 CVEs tagged with CWE-91525 Critical, 64 High, 41 Medium, 7 Low, 0 Unrated.

CVE-2026-63428

Published Jul 20, 2026

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id, name, value}]` array from the submitter and stores it verb…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-63102

Published Jul 20, 2026

rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-56679

Published Jul 15, 2026

9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body to persistent settings without a field whitelist, allowing a…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59888

Published Jul 14, 2026

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-58477

Published Jul 14, 2026

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration se…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-55810

Published Jul 10, 2026

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Gra…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55804

Published Jul 10, 2026

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55803

Published Jul 10, 2026

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-15083

Published Jul 10, 2026

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-13244

Published Jul 10, 2026

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injection. This issue affects Tealiu…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-12535

Published Jul 10, 2026

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-9726

Published Jul 10, 2026

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affe…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-59721

Published Jul 9, 2026

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts an attacker-controlled MAILER…

CVSS 7.2 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-54601

Published Jul 7, 2026

FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT allows an authenticated tenant user to call POST /api/core/dataset/collection/cr…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-43925

Published Jul 6, 2026

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in the client self-registration e…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-50281

Published Jul 2, 2026

Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw in the bulk-duplicate element action. An attacker who is o…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-50160

Published Jul 1, 2026

Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated POST /v1/onboarding/config endp…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-55223

Published Jun 30, 2026

c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deserialization gadgets. The JDBC s…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-54351

Published Jun 26, 2026

Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HTTP request body into automatio…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48943

Published Jun 25, 2026

K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=1` in a standard `com_users` `…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45687

Published Jun 24, 2026

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's sendFileMe…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-54516

Published Jun 23, 2026

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._re…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-54515

Published Jun 23, 2026

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializer…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-55736

Published Jun 23, 2026

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument that is…

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
27.6
Showing 1-25 of 137 CVEsPage 1 of 6