CVE-2025-50904: Winterchens My-Site
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can exploit this vulnerability to access /admin/ API without any token.
Affected products
- Winterchens My-Site: up to and including 2025-06-11
Published 2025-08-20. Last modified 2026-06-17.