Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

B1Scuit

#26749of 53,625
9.5Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-45278
4.0
2026-06-01
Mettle · Sendportal · CVE-2026-10234
A vulnerability was detected in Mettle sendportal up to 3.0.1. This affects an unknown part of the file /webview/ of the component Campaign Handler. The manipulation of the argument content results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
PT-2026-35500
5.5
2026-04-27
Mettle · Sendportal · CVE-2026-7145
**Name of the Vulnerable Software and Affected Versions** mettle sendportal versions prior to 3.0.2 **Description** An authorization bypass exists in the Invitation Handler component. A remote attacker can manipulate the `invitation` argument within the `destroy()` function of the 'app/Http/Controllers/Workspaces/WorkspaceInvitationsController.php' file to bypass authorization controls. **Recommendations** Update to a version newer than 3.0.1. As a temporary workaround, restrict access to the `destroy()` function in the 'app/Http/Controllers/Workspaces/WorkspaceInvitationsController.php' file.