CVE-2026-13546

Source
https://cve.org/CVERecord?id=CVE-2026-13546
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-13546.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-13546
Published
2026-06-29T07:15:07.559Z
Modified
2026-07-15T01:49:19.345907188Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Feehi CMS REST API Endpoint articles missing authentication
Details

A vulnerability was found in Feehi CMS up to 2.1.1. This vulnerability affects unknown code of the file /api/articles of the component REST API Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cwe_ids": [
        "CWE-287",
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/13xxx/CVE-2026-13546.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/liufee/cms

Affected ranges

Type
GIT
Repo
https://github.com/liufee/cms
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.1.0"
        },
        {
            "last_affected": "2.1.0"
        },
        {
            "introduced": "2.1.1"
        },
        {
            "last_affected": "2.1.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2.*
2.1.0
2.1.0.1
2.1.0.2
2.1.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-13546.json"