PoC Archive PoC Archive

tag

Broken-Access-Control

Critical
Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)
CVE-2025-13342· Frontend Admin by DynamiApps (WordPress plugin built on Advanced Custom Fields / ACF frontend forms) patched
Medium
YAMCS Unauthorized User Enumeration via IAM API (CVE-2026-44595)
CVE-2026-44595 / GHSA-p2rj-mrmc-9w29· yamcs-core (YAMCS mission control software) patched
Not disclosed
WooCommerce Frontend Registration Form Unauthenticated Admin Role Assignment — CVE-2026-54807
CVE-2026-54807· WordPress plugin exposing a custom WooCommerce-style frontend registration form (form fields prefixed tgwcfb_*) unpatched
High
Simple History Missing Authorization Account Takeover — CVE-2026-7459
CVE-2026-7459· Simple History (WordPress plugin) unpatched
High
Masteriyo LMS Authenticated Privilege Escalation to Administrator (CVE-2026-4484)
CVE-2026-4484· Masteriyo LMS plugin for WordPress unpatched
High
LiteLLM Proxy Privilege Escalation via `/user/update` (CVE-2026-47102)
CVE-2026-47102· LiteLLM (LLM API proxy / gateway) patched
High
LiteLLM /config/update Broken Access Control (CVE-2026-35029)
CVE-2026-35029· LiteLLM proxy patched
High
Grafana Dashboard Permissions Broken Access Control — Editor-to-Admin Privilege Escalation (CVE-2026-21721)
CVE-2026-21721· Grafana (self-hosted, dashboard permissions API) unpatched
High
GitLab WebSocket GraphqlChannel Unauthorized Method Enumeration — CVE-2026-5173
CVE-2026-5173· GitLab CE/EE, ActionCable WebSocket endpoint (/-/cable), GraphqlChannel patched
High
Eventin (wp-event-solution) Broken Access Control / IDOR (CVE-2026-40776)
CVE-2026-40776 / Patchstack PSID 85de025d71e7· Eventin — Events Calendar, Event Booking, Ticket & Registration (wp-event-solution WordPress plugin) patched
High
Azuriom CMS Broken Access Control — Account Takeover via AzLink Server Token — CVE-2026-54415
CVE-2026-54415· Azuriom CMS patched