Loading market data...
← Back to CVE feed

CVE-2026-88421

HIGH CVSS 7.5 View on NVD ↗

Description

Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, category, author and date archives, the sidebar widgets, or the RSS feed.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Published: Sep 25, 2026 13:17 UTC Modified: Sep 25, 2026 17:17 UTC