Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

B1Scuit

#27499of 55,119
9.5Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-45278
4.0
2026-06-01
Mettle · Sendportal · CVE-2026-10234
**Name of the Vulnerable Software and Affected Versions** Mettle sendportal versions prior to 3.0.2 **Description** A cross site scripting issue exists in the Campaign Handler component within the `/webview/` file. A remote attacker can trigger this by manipulating the `content` argument. Cross site scripting is a technique where malicious scripts are injected into trusted websites. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-35500
5.5
2026-04-27
Mettle · Sendportal · CVE-2026-7145
**Name of the Vulnerable Software and Affected Versions** mettle sendportal versions prior to 3.0.2 **Description** An authorization bypass exists in the Invitation Handler component. A remote attacker can manipulate the `invitation` argument within the `destroy()` function of the 'app/Http/Controllers/Workspaces/WorkspaceInvitationsController.php' file to bypass authorization controls. **Recommendations** Update to a version newer than 3.0.1. As a temporary workaround, restrict access to the `destroy()` function in the 'app/Http/Controllers/Workspaces/WorkspaceInvitationsController.php' file.