CVE-2013-2629: Idleman Leed
Medium severity, CVSS 5.0. EPSS: 1.4% chance of exploitation in the next 30 days.
Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to bypass authorization via vectors related to the (1) importForm, (2) importFeed, (3) addFavorite, or (4) removeFavorite actions in action.php.
Affected products
- Idleman Leed: up to and including 1.4
Published 2013-12-23. Last modified 2026-06-16.