All CosmicBytez Labs articles tagged #REST API, across news, security advisories, how-to guides, and projects.
CVE-2026-82452 (CVSS 9.8): rust-iot-platform's REST API lacks auth checks — anyone can create, edit, or delete accounts, no login required.
Security Hardener plugin up to 2.4.4 overwrites REST endpoint permissions via rest_endpoints filter, bypassing all registered auth callbacks.
High-severity unauthenticated SQL injection in Object Sync for Salesforce plugin allows attackers to extract data via a misconfigured REST API push endpoint.
A critical CVSS 9.1 access control flaw in the WP Travel Pro WordPress plugin allows unauthenticated attackers to delete any user account — including...
CVSS 9.8 in Goobi Viewer REST API lets unauthenticated clients inject Solr streaming expressions, enabling RCE on affected digital heritage platforms.
A CVSS 10.0 authentication bypass in Cisco Secure Workload allows unauthenticated remote attackers to access internal REST APIs with full Site Admin privileges.
A critical arbitrary file upload vulnerability in CubeCart's REST API File Manager allows holders of a files:rw API key to upload PHP webshells to the web...
MStore API 2.0.6 for WordPress allows unauthenticated attackers to upload arbitrary PHP files via the REST API config_file endpoint, achieving remote code...
A critical CVSS 9.8 vulnerability in the Quick Playground WordPress plugin (versions up to 1.3.1) allows unauthenticated attackers to upload arbitrary...