CWE-346

CWE-346 · 18 records · 10 with a public proof-of-concept

Records the NVD classes under CWE-346, highest CVSS first.

  1. HIGH 8.8CVE-2026-85682

    The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possi…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.1CVE-2026-100646public PoC

    SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authentication guards (CheckAuth in kernel/model/session.go and IsSessionOriginAllowed in kernel/util/net.go) fail open when the HTTP Origin heade…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.1CVE-2026-86466public PoC

    Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a different client applic…

    apache-airflow-providers-fab

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.6CVE-2026-100642public PoC

    SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests without validating Origin headers. Attackers can craft malicious…

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.3CVE-2026-94243

    A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to upgrade to version 1.3.2, which fixes the issue.

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.1CVE-2026-100598public PoC

    OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a reaction intended to resolve a structured approval request could instead attach to ordinary outbound text when unrelated outbound messages and …

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 6.6CVE-2026-94111public PoC

    Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a brows…

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 6.5CVE-2026-97155

    Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. The registry value VALIDDOMAINS, which limits per…

    AI risk analysis on Exploit-DB.ai →

  9. MEDIUM 6.3CVE-2026-92360public PoC

    A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START causes origin valida…

    AI risk analysis on Exploit-DB.ai →

  10. MEDIUM 5.9CVE-2026-77119

    A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.…

    AI risk analysis on Exploit-DB.ai →

  11. MEDIUM 4.7CVE-2026-75025

    Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources. Thanks to game0v3r for contributing to this improvement under the Mat…

    AI risk analysis on Exploit-DB.ai →

  12. MEDIUM 4.3CVE-2026-101278

    A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_get_tld of the file libopendmarc/opendmarc_tld.c : of the component PSL Wildcard Handler. Executing a manipulation can lead to origin validation…

    AI risk analysis on Exploit-DB.ai →

  13. MEDIUM 4.3CVE-2026-91132public PoC

    Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, sites using wildcard patterns in the allowed_iframes setting could accept a crafted iframe URL whose allowlisted suffix appeared after a URL authority separat…

    AI risk analysis on Exploit-DB.ai →

  14. LOW 3.7CVE-2026-12284

    Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an active call belonging t…

    AI risk analysis on Exploit-DB.ai →

  15. LOW 3.4CVE-2026-92706public PoC

    Dark Reader is an accessibility browser extension that makes web pages colors dark. Prior to 4.9.126, a website can cause the browser extension's image inversion pipeline to request an unauthenticated icon-like bitmap from a locally running web server when the…

    AI risk analysis on Exploit-DB.ai →

  16. LOW 3.1CVE-2026-92359public PoC

    A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_app of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component CORSMiddleware. The manipulation results in permi…

    AI risk analysis on Exploit-DB.ai →

  17. UNSCOREDCVE-2026-18825

    An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request.

    AI risk analysis on Exploit-DB.ai →

  18. UNSCOREDCVE-2026-61742public PoC

    DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when started with the documented HTTP transport mode, for example `--transport http --port 8080`. The …

    AI risk analysis on Exploit-DB.ai →