webverselabs-pro 23
- Unrestricted File Upload Leads to Remote Code Execution | Calliope Gallery
- XXE Injection via Envelope Import Leads to Arbitrary File Read | Foldmark
- Local File Inclusion via Template Router | CostThis
- IDOR in Password Reset API Leads to Administrator Account Takeover | TheForms
- JWT Algorithm Confusion Leads to Privilege Escalation | Halftone Studio
- Password Change IDOR Leads to Administrator Account Takeover | Noted
- NoSQL Injection Leads to Treasury Account Takeover | Coined
- Multi-Step Access Control Bypass Leads to Administrative Compromise | Tamper Temple
- Local File Inclusion via Language Cookie Leads to Arbitrary File Read | Flagged
- Exposed Git Repository Leads to Administrative Credential Disclosure | Fault Banking
- NoSQL Injection via Search Filter Object Leads to Hidden Rental Disclosure | SwiftSearch Hotels
- GraphQL Role Parameter Abuse Leads to Restricted Medical Note Disclosure | Clearance
- SQL Injection in Voucher Search Leads to Executive Voucher Disclosure | Voucher Vault
- SQL Injection via Issue Identifier Parameter | Trace Control
- OS Command Injection via Archive Export Filename | Parchive
- IDOR – Unauthorized Grant Approval via Workflow Manipulation | Briarcliff Foundation
- Next.js Middleware Authorization Bypass (CVE-2025-29927) | BugVault
- Authentication Bypass via Forged Remember-Me Cookie | Skein
- NoSQL Injection Authentication Bypass | Herbalist Remedies
- Exposed Git Repository Information Disclosure | Loop & Roam Records
- Default Credentials Authentication Weakness | Lake Forks Permits
- Local File Inclusion via Double URL Encoding | Mirage
- OS Command Injection in Network Diagnostics | Netcheck