Common Vulnerabilities and Exposures (CVE)

CVE-2026-72711

Aug 29, 2026 11:47:45 UTC

The Lean 4 kernel does not check that the body of an opaque declaration is closed. environment::add_opaque omits the check_no_metavar_no_fvar call that the definition and theorem paths perform, so a value containing a free variable that is ...

CVE-2026-72705

Aug 29, 2026 11:47:44 UTC

The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own arguments. A fixpoint may pass itself as a higher-order argument to a second fixpoint, which then applies it to a value that is not a subterm of ...

CVE-2026-72704

Aug 29, 2026 11:47:43 UTC

The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after that parameter has been changed by transport. A fixpoint may apply a rewrite along an equality between types to its rec...

CVE-2026-72703

Aug 29, 2026 11:47:43 UTC

The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without examining calls between the different bodies of that fixpoint. find_uniform_parameters in kernel/inductive.ml inspects only self-recursive ca...

CVE-2026-72699

Aug 29, 2026 11:47:42 UTC

The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address already b...

CVE-2026-71511

Aug 29, 2026 11:47:41 UTC

Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password verifiers by querying member endpoints. Attackers can ca...

CVE-2026-71510

Aug 29, 2026 11:47:40 UTC

Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses without...

CVE-2026-71509

Aug 29, 2026 11:47:40 UTC

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass the approval workflow by directly setting appr...

CVE-2026-71508

Aug 29, 2026 11:47:38 UTC

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits pa...

CVE-2026-71507

Aug 29, 2026 11:47:38 UTC

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank acco...

CVE-2026-71506

Aug 29, 2026 11:47:37 UTC

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the inte...

CVE-2026-71505

Aug 29, 2026 11:47:36 UTC

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal password...

CVE-2026-71504

Aug 29, 2026 11:47:36 UTC

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without ve...

CVE-2026-71503

Aug 29, 2026 11:47:35 UTC

Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no Con...

CVE-2026-6827

Aug 29, 2026 11:47:34 UTC

justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve foreign namespaces (SVG/MathML), dangerous content such as HTML integration points (SVG <f...