CVE-2026-88421
Last modified
CVE-2026-88421 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, category, author and date archives, the sidebar widgets, or the RSS feed..
Description
Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, category, author and date archives, the sidebar widgets, or the RSS feed.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-88421?
How severe is CVE-2026-88421?
How do I fix CVE-2026-88421?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-88415MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site …8.7
- CVE-2026-88416MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability i…
- CVE-2026-88418CMSimple 5.24 ships with CSRF protection disabled by default…8.8
- CVE-2026-88419An unrestricted upload of files with a dangerous type in the…8.8
- CVE-2026-8842The Google+ Link Name plugin for WordPress is vulnerable to …6.4
- CVE-2026-88420A reflected cross-site scripting (XSS) vulnerability in the …
- CVE-2026-8843Creating a "2dsphere_bucket" index on a non-timeseries bucke…6.5
- CVE-2026-8844The Responsive Check plugin for WordPress is vulnerable to S…6.4
- CVE-2026-8845The Islamic Database plugin for WordPress is vulnerable to S…6.4
- CVE-2026-8846The Tuxquote plugin for WordPress is vulnerable to Stored Cr…6.4
- CVE-2026-88467CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a bac…
- CVE-2026-8847The Dideo plugin for WordPress is vulnerable to Stored Cross…6.4
Are you affected by CVE-2026-88421?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
