Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103396 | 1 Bbs-go Project | 1 Bbs-go | 2026-09-30 | 4.3 Medium |
| bbs-go through 4.4.6 contains a permission bypass vulnerability in the AdminMiddleware authorization logic where the read-only dashboard.user.view permission rule matches the /api/admin/user/synccount endpoint before the intended dashboard.user.update rule. Authenticated users with only view permissions can call the synccount endpoint to trigger expensive full-table user recounts and cache invalidations, causing denial of service through repeated concurrent database operations. | ||||
| CVE-2021-38221 | 1 Bbs-go Project | 1 Bbs-go | 2024-11-21 | 5.4 Medium |
| bbs-go <= 3.3.0 including Custom Edition is vulnerable to stored XSS. | ||||
Page 1 of 1.
