Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-92765 1 Archerysec 1 Archery 2026-09-16 6.5 Medium
ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses, and analyst notes from other tenants.
CVE-2019-20008 1 Archerysec 1 Archery 2024-11-21 5.4 Medium
In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an existing one) will result in stored XSS on the vulnerability-scan scheduling page.