CVE-2026-107793: Banq Jivejdon
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Jivejdon through 5.0 contains an authorization bypass vulnerability in SubscriptionServiceImp.deleteSubscription that allows authenticated users to delete other users' subscriptions by ID. Attackers can submit a delete action to /account/protected/sub/subSaveAction with another user's subscriptionId to remove their thread, forum, tag or account subscriptions.
Affected products
- Banq Jivejdon: up to and including 5.0
Published 2026-10-08. Last modified 2026-10-09.