CVE-2026-88421
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, category, author and date archives, the sidebar widgets, or the RSS feed.
Published 2026-09-25. Last modified 2026-09-30.