Logo

CVEs

A curated list of CVEs I’ve picked up so far.

11 published entries

CVE-2026-50199 Wallos Moderate

Cross-user Fixer/API Layer credential consumption in exchange-rate refresh let one user trigger provider-backed actions through another user's stored credential.

June 5, 2026
CVE-2026-50198 Wallos Moderate

Cross-user subscription cost inference via replacement_subscription_id let an authenticated user infer another user subscription cost through unscoped stats dereferencing.

June 5, 2026
CVE-2026-48067 Filament Moderate

Inconsistent scope enforcement for AttachAction and AssociateAction Select fields let out-of-scope records pass through backend validation.

May 25, 2026
CVE-2026-47755 ITFlow Moderate

Authenticated cross-tenant credential disclosure exposed another client secrets through an unprotected credential modal.

May 25, 2026
CVE-2026-47745 Shopper Moderate

Payment methods, currencies, and carriers exposed inline toggles and record actions without proper per-action authorization checks.

May 22, 2026
CVE-2026-47742 Shopper Moderate

Product editor sub-form Livewire components accepted unauthorized store actions and allowed tampering without the required permission.

May 22, 2026
CVE-2026-47740 Shopper High

Missing authorization on order mutation actions let low-privileged authenticated users mutate order state without the required write permission.

May 22, 2026
CVE-2026-44692 Sharp High

A generic download endpoint let authenticated users use one valid record as an authorization anchor to download unrelated Laravel Storage objects.

May 8, 2026