CVE-2026-65758
The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.
CVSS
—
Sin CVSS
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 23 jul 2026 · Última mod.: 23 jul 2026 · CWE-200 · CWE-284
Sin historial EPSS suficiente todavía.
The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-65757—2.8%
——1The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens.7hCVE-2026-65430—8.9%
——3MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.7hCVE-2026-64876—2.8%
——1Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.7hCVE-2026-64874—8.9%
——3CDN credentials were exposed in administrator request URLs.7hCVE-2026-64871—2.8%
——1Administrator URL purges did not consistently require a valid token and cache-management permission.7hCVE-2024-583307.5 ALT39.9%
——12A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.8h