tag
Broken-Access-Control
Critical
Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)
CVE-2025-13342·
Frontend Admin by DynamiApps (WordPress plugin built on Advanced Custom Fields / ACF frontend forms)
patched
Medium
YAMCS Unauthorized User Enumeration via IAM API (CVE-2026-44595)
CVE-2026-44595 / GHSA-p2rj-mrmc-9w29·
yamcs-core (YAMCS mission control software)
patched
Not disclosed
WooCommerce Frontend Registration Form Unauthenticated Admin Role Assignment — CVE-2026-54807
CVE-2026-54807·
WordPress plugin exposing a custom WooCommerce-style frontend registration form (form fields prefixed tgwcfb_*)
unpatched
High
Simple History Missing Authorization Account Takeover — CVE-2026-7459
CVE-2026-7459·
Simple History (WordPress plugin)
unpatched
High
Masteriyo LMS Authenticated Privilege Escalation to Administrator (CVE-2026-4484)
CVE-2026-4484·
Masteriyo LMS plugin for WordPress
unpatched
High
LiteLLM Proxy Privilege Escalation via `/user/update` (CVE-2026-47102)
CVE-2026-47102·
LiteLLM (LLM API proxy / gateway)
patched
High
LiteLLM /config/update Broken Access Control (CVE-2026-35029)
CVE-2026-35029·
LiteLLM proxy
patched
High
Grafana Dashboard Permissions Broken Access Control — Editor-to-Admin Privilege Escalation (CVE-2026-21721)
CVE-2026-21721·
Grafana (self-hosted, dashboard permissions API)
unpatched
High
GitLab WebSocket GraphqlChannel Unauthorized Method Enumeration — CVE-2026-5173
CVE-2026-5173·
GitLab CE/EE, ActionCable WebSocket endpoint (/-/cable), GraphqlChannel
patched
High
Eventin (wp-event-solution) Broken Access Control / IDOR (CVE-2026-40776)
CVE-2026-40776 / Patchstack PSID 85de025d71e7·
Eventin — Events Calendar, Event Booking, Ticket & Registration (wp-event-solution WordPress plugin)
patched
High
Azuriom CMS Broken Access Control — Account Takeover via AzLink Server Token — CVE-2026-54415
CVE-2026-54415·
Azuriom CMS
patched