CVE-2026-28104: Aryan Shirani Bid Abadi Site Suggest
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Missing Authorization vulnerability in Aryan Shirani Bid Abadi Site Suggest site-suggest allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Site Suggest: from n/a through <= 1.3.9.
Affected products
- Aryan Shirani Bid Abadi Site Suggest: up to and including 1.3.9
Published 2026-03-05. Last modified 2026-06-17.