Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-107793

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Oct 08, 2026
Vendor unknown

Description

Jivejdon through 5.0 contains an authorization bypass vulnerability in SubscriptionServiceImp.deleteSubscription that allows authenticated users to delete other users' subscriptions by ID. Attackers can submit a delete action to /account/protected/sub/subSaveAction with another user's subscriptionId to remove their thread, forum, tag or account subscriptions.

References