CVE-2026-18258
- EPSS 0.31%
- Veröffentlicht 06.08.2026 15:11:28
- Zuletzt bearbeitet 18.08.2026 18:05:06
Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary...
CVE-2026-18277
- EPSS 0.24%
- Veröffentlicht 06.08.2026 15:11:23
- Zuletzt bearbeitet 18.08.2026 18:06:35
Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via...
CVE-2026-18359
- EPSS 0.22%
- Veröffentlicht 06.08.2026 15:11:13
- Zuletzt bearbeitet 18.08.2026 18:06:45
Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata ...
CVE-2026-18275
- EPSS 0.23%
- Veröffentlicht 06.08.2026 15:11:08
- Zuletzt bearbeitet 18.08.2026 18:05:16
Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their content, v...
CVE-2026-18276
- EPSS 0.27%
- Veröffentlicht 06.08.2026 15:11:03
- Zuletzt bearbeitet 18.08.2026 18:05:23
Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training...