CVE-2026-10285
A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper
CVSS
5.4
Medio
EPSS
0.2%
p14
KEV
—
Exploit Today
4
0-100
Publicado: 1 jun 2026 · Última mod.: 22 jul 2026 · CWE-266 · CWE-285
0.2%EPSS · 30 días0.2%
2026-07-272026-08-24
A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the component Ticket Handler. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-782679.8 CRÍ—
——0Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.21hCVE-2026-325618.8 ALT—
——0Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.11hCVE-2026-217567.2 ALT—
——0HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments.1dCVE-2026-666489.8 CRÍ—
——0Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.1dCVE-2026-325589.8 CRÍ—
——0Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.1dCVE-2026-281659.8 CRÍ—
——0Unauthenticated Privilege Escalation in Digits <= 9.2 versions.1d