CWE-915

CWE-915 · 7 records · 7 with a public proof-of-concept

Records the NVD classes under CWE-915, highest CVSS first.

  1. HIGH 8.5CVE-2026-76086public PoC

    Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings control panel action in IntegrationsController::actionFormSettings is reachable without the required form integration permissions and passes…

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 6.3CVE-2026-92217public PoC

    A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message Parsing. This manipulation causes dynamically-determine…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 4.3CVE-2026-93364public PoC

    Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save request. Attackers can sub…

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 4.3CVE-2026-61834public PoC

    scim-patch is a library for applying SCIM patch operations. Prior to 0.9.2, navigate() reads inherited properties and assign() uses prototype-chain membership checks while resolving attacker-controlled SCIM PATCH paths. A path or one of the dotted value keys b…

    AI risk analysis on Exploit-DB.ai →

  5. UNSCOREDCVE-2026-93477public PoC

    Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the bulk destroy and bulk update paths. Action arguments declared with public?: fals…

    AI risk analysis on Exploit-DB.ai →

  6. UNSCOREDCVE-2026-61598public PoC

    djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.mixins.model_binding.ModelBindingMixin` provides a default `update_model` event handler and is part of the LiveView ba…

    AI risk analysis on Exploit-DB.ai →

  7. UNSCOREDCVE-2026-69258public PoC

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowD…

    AI risk analysis on Exploit-DB.ai →