CVE-2026-106596 — Missing Authorization vulnerability in Visual Composer Visual Composer Website Builder visualcomposer allows Exploiting Incorrectly Configured Acce…
Description
Missing Authorization vulnerability in Visual Composer Visual Composer Website Builder visualcomposer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Visual Composer Website Builder: from n/a through 45.16.3.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
Low
Confidentiality
I
None
Integrity
A
None
Availability
Related threats
same CWE or vendorCVE-2026-107792 — Jivejdon from commit d58a36b0 through commit ee67a65e contains a missing authorization vulnerability in UpdateThreadToForumAction that allows authe…
CVE-2026-107792 · 1h ago
CVE-2026-107725 — Hazelcast is a unified real-time data platform combining stream processing with a fast data store.
CVE-2026-107725 · 1h ago
CVE-2026-107395 — Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.
CVE-2026-107395 · 3h ago
CVE-2026-93860 — In OpenStack Mistral through 23.0.0, the /v2/maintenance API controller clears the request context and calls the maintenance service directly witho…
CVE-2026-93860 · 5h ago
CVE-2026-12859 — Missing Authorization vulnerability in Caz Informatics Services Trade Inc.
CVE-2026-12859 · 8h ago
CVE-2026-107623 — A flaw was found in the OIDC Dynamic Client Registration (DCR) component of Keycloak.
CVE-2026-107623 · 8h ago