CVE-2025-46720 Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields

Keystone is a content management system for Node.js. Prior to version 6.5.0, {field}.isFilterable access control can be bypassed in update and delete mutations by adding additional unique filters. The ...

Continue Reading
CVE-2025-46720

Keystone is a content management system for Node.js. Prior to version 6.5.0, {field}.isFilterable access control can be bypassed in update and delete mutations by adding additional unique filters. The ...

Continue Reading
CVE-2025-46720

Keystone is a content management system for Node.js. Prior to version 6.5.0, {field}.isFilterable access control can be bypassed in update and delete mutations by adding additional unique filters. The ...

Continue Reading
CVE-2025-32354

In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of Zimbra webmail due to a lack of CSRF to ...

Continue Reading
CVE-2025-32354

In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of Zimbra webmail due to a lack of CSRF to ...

Continue Reading
CVE-2025-32354

In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of Zimbra webmail due to a lack of CSRF to ...

Continue Reading
CVE-2025-32354

In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/graphql) of Zimbra webmail due to a lack of CSRF to ...

Continue Reading
Security Bulletin: IBM FileNet Content Manager GraphQL Cross-site request forgery security vulnerability

Summary IBM FileNet Content Manager in GraphQL, there is a Cross-site request forgery security vulnerability. Vulnerability Details CVEID:CVE-2020-4745 DESCRIPTION: IBM FileNet Content Manager is vuln ...

Continue Reading

Back to Main

Subscribe for the latest news: