Filtered by vendor Konga Project Subscriptions
Filtered by product Konga Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-42192 1 Konga Project 1 Konga 2024-08-04 8.8 High
Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.
CVE-2023-26987 1 Konga Project 1 Konga 2024-08-02 6.5 Medium
An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.