Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Nuiifornet

#22771of 55,131
10.6Total CVSS
Vulnerabilities · 2
Low
1
High
1
PT-2026-67413
7.5
2026-08-03
Admidio · Admidio · CVE-2026-69091
Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in modules/forum.php fails to validate the login-only configuration state, allowing unauthenticated attackers to read forum topics and posts by directly accessing the module with read-only parameters.
PT-2026-43305
3.1
2026-05-26
Bugsink · Bugsink · CVE-2026-47715
**Name of the Vulnerable Software and Affected Versions** Bugsink versions prior to 2.2.0 **Description** Bugsink is a self-hosted error tracking tool. A project-boundary authorization issue exists where issue event pages accept a direct event identifier from the URL and retrieve the event without verifying that it belongs to the issue specified in the URL. This allows an authenticated user with access to one project to view event data from another project through an issue they are authorized to access. The affected views include the stacktrace, details, and breadcrumbs pages. Exploitation requires the attacker to possess a valid target event UUID, as there is no path for event enumeration and guessing UUIDs is impractical. **Recommendations** Update to version 2.2.0.