CVE-2026-105131
- EPSS 0.2%
- Veröffentlicht 04.10.2026 01:20:29
- Zuletzt bearbeitet 06.10.2026 15:25:00
ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because TokenRefreshHandler never checks token type, attackers c...
CVE-2026-94112
- EPSS 0.23%
- Veröffentlicht 20.09.2026 11:56:07
- Zuletzt bearbeitet 24.09.2026 21:08:55
mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multi...
CVE-2025-65519
- EPSS 0.29%
- Veröffentlicht 18.02.2026 00:00:00
- Zuletzt bearbeitet 20.02.2026 20:08:11
mayswind ezbookkeeping versions 1.2.0 and earlier contain a critical vulnerability in JSON and XML file import processing. The application fails to validate nesting depth during parsing operations, allowing authenticated attackers to trigger denial o...
CVE-2024-57604
- EPSS 0.72%
- Veröffentlicht 12.02.2025 22:15:41
- Zuletzt bearbeitet 06.06.2025 17:57:47
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
CVE-2024-57603
- EPSS 0.44%
- Veröffentlicht 12.02.2025 22:15:40
- Zuletzt bearbeitet 06.06.2025 17:53:07
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting.