CrossSite Request Forgery to Vendor Updates vulnerability
23 October, 2024
Missing Authorization to Forged Vendor Profile Deletion Email Sending vulnerability
23 October, 2024
Missing Authorization to Limited Vendor Privilege Escalation/Account Takeover vulnerability
4 September, 2024
Reflected Cross Site Scripting (XSS) vulnerability
9 August, 2024
Authenticated (Contributor+) Stored CrossSite Scripting via hover_animation Parameter vulnerability
6 June, 2024