该漏洞允许任何已认证用户无需提供当前密码或处于提权会话中,即可修改自己的密码。此外,如果攻击者的账户拥有“编辑用户”权限(该权限本不应允许修改他人密码),但缺乏“管理用户”权限(该权限才是修改他人密码所必需的),则攻击者还可以修改其他用户的密码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84795 | 9.8 CRITICAL | Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance |
| CVE-2026-84801 | 8.8 HIGH | Craft CMS 5.0.0-RC1 before 5.10.11 Authentication Bypass via administrateUsers |
| CVE-2026-84796 | 8.8 HIGH | Craft CMS 5.0.0-RC1 before 5.10.11 GraphQL Entry Mutation Site Scope Bypass |
| CVE-2026-79990 | 8.7 HIGH | GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/w |
| CVE-2026-84794 | 7.1 HIGH | Craft CMS 5.0.0 through 5.10.10 Authorization Bypass via assets/move-asset |
| CVE-2026-84800 | 7.1 HIGH | Craft CMS 5.0.0-RC1 before 5.10.11 File Overwrite via assets/replace-file |
| CVE-2026-84798 | 7.1 HIGH | Craft CMS before 5.10.11 Authorization Bypass via actionDeleteForSite |
| CVE-2026-79991 | 7.1 HIGH | Authenticated SQL Injection via nested eager-loading criteria |
| CVE-2026-84797 | 6.3 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.11 Authorization Bypass via actionDuplicate |
| CVE-2026-84793 | 4.8 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.11 Stored XSS via site name |
| CVE-2026-84792 | 4.3 MEDIUM | Craft CMS before 5.10.11 Broken Access Control via element-indexes |
| CVE-2026-84802 | 4.3 MEDIUM | Craft CMS 5.7.0 before 5.10.12 Information Disclosure via AssetsController |
| CVE-2026-84799 | 4.3 MEDIUM | Craft CMS before 5.11.0 PII Disclosure via GraphQL User Relations |
No comments yet