CVE-2026-94498
Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.
CVSS
6.5
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 23, 2026 · Last modified: Sep 23, 2026 · CWE-862
Not enough EPSS history yet.
Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-956047.5 HIG—
——0Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.1hCVE-2026-955276.5 MED—
——0Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.1hCVE-2026-955137.5 HIG—
——0Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.1hCVE-2026-946795.4 MED—
——0Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.1hCVE-2026-940805.3 MED—
——0Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.1hCVE-2026-940795.3 MED—
——0Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions.1h