CVE-2025-50904: Winterchens My-Site

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can exploit this vulnerability to access /admin/ API without any token.

Affected products

Published 2025-08-20. Last modified 2026-06-17.