Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-108904 — pH7Builder before 18.5.0 Sensitive Data Exposure via Member API UserController

pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an information disclosure vulnerability that allows API clients to obtain sensitive member data because UserController::users() and user() re…

Remote | Information Disclosure
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
6.9 MEDIUM
CVE-2026-108903 — pH7Builder before 19.3.0 CAPTCHA Bypass via Client-Chosen Form ID

pH7Builder (pH7 Social Dating CMS) before 19.3.0 contains a CAPTCHA bypass vulnerability that allows unauthenticated attackers to skip form validation by supplying a client-chosen form ID to PFBC For…

Remote | Authentication
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
8.1 HIGH
CVE-2026-108902 — pH7Builder before 18.5.0 Path Traversal Arbitrary File Deletion via picture_link

pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains a path traversal vulnerability in the picture module deletePhoto() action that allows authenticated members to delete arbitrary files. Attack…

Remote | Path Traversal
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108891 — JeecgBoot through 3.9.5 Missing Authorization via /sys/user/getUserDetailByUserId

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController getUserDetailByUserId handler that allows any authenticated user to read other users' details. Low-priv…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108888 — JeecgBoot through 3.9.5 Missing Authorization via /sys/sysDepartRole/exportXls

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartRoleController exportXls handler that allows any authenticated user to export department roles. Low-privileged a…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108887 — JeecgBoot through 3.9.5 Missing Authorization via /sys/comment/exportXls

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCommentController exportXls handler that allows any authenticated user to export all comments. Low-privileged attacker…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108886 — JeecgBoot through 3.9.5 Missing Authorization via /sys/user/queryChildrenByUsername

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController queryChildrenByUsername handler that allows any authenticated user to retrieve other users' account rec…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.4 MEDIUM
CVE-2026-108885 — JeecgBoot through 3.9.5 Missing Authorization via /sys/message/sysMessage/delete

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController delete handler that allows low-privileged authenticated users to delete message records. Attackers c…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.4 MEDIUM
CVE-2026-108884 — JeecgBoot through 3.9.5 Missing Authorization via sysMessageTemplate Delete Endpoint

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageTemplateController delete handler that allows any authenticated user to delete message templates. Low-privilege…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
7.1 HIGH
CVE-2026-108883 — JeecgBoot through 3.9.5 Missing Authorization via /sys/thirdApp/editThirdAppConfig

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the editThirdAppConfig handler that allows any authenticated user to modify third-party application configurations. Low-privi…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.4 MEDIUM
CVE-2026-108882 — JeecgBoot through 3.9.5 Missing Authorization via /sys/position/removePositionUser

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController removeUserPosition handler that allows any authenticated user to remove position members. Low-privi…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108881 — JeecgBoot through 3.9.5 Missing Authorization via /sys/tenant/getTenantPackInfo

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the getTenantPackInfo handler that allows any authenticated user to read other tenants' product pack membership. Low-privileg…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108880 — JeecgBoot through 3.9.5 Missing Authorization via /sys/dict/editDictByLowAppId

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the PUT /sys/dict/editDictByLowAppId endpoint that allows any authenticated user to modify low-code application dictionaries.…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108879 — JeecgBoot through 3.9.5 IDOR via /airag/api/getChatVariable Username Parameter

JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability in AiragBaseApiController that allows authenticated users to read other users' AI chat variables via the username pa…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108878 — JeecgBoot through 3.9.5 Missing Authorization via /airag/app/queryById

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragAppController queryById handler that allows low-privileged authenticated users to read any AI application configurat…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.4 MEDIUM
CVE-2026-108877 — JeecgBoot through 3.9.5 Missing Authorization via /airag/prompts/delete

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in AiragPromptsController that allows any authenticated user to delete AI prompt templates by calling DELETE /airag/prompts/dele…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108876 — JeecgBoot through 3.9.5 Missing Authorization via /sys/user/putCancelQuit

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the putCancelQuit handler of SysUserController, allowing any authenticated user to cancel user resignations. Low-privileged a…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108875 — JeecgBoot through 3.9.5 Missing Authorization via /sys/user/addSysUserGroup

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController addSysUserGroup handler that allows any authenticated user to modify user group membership. Low-privile…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108874 — JeecgBoot through 3.9.5 Missing Authorization via /sys/user/changeDepartChargePerson

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to assign or remove department heads by calling PUT /sys/user/changeDepartChargePerson. Low-p…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
5.3 MEDIUM
CVE-2026-108873 — JeecgBoot through 3.9.5 Missing Authorization via /sys/user/doUpdateDepartInfo

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to modify any department by calling PUT /sys/user/doUpdateDepartInfo. Attackers c…

jeecg_boot | Remote | Authorization
Oct 11, 2026 Oct 11, 2026
Oct 11, 2026
Oct 11, 2026
Showing 20 of 13681 Results