Saad Iqbal Mycred vulnerabilities

10 known vulnerabilities affecting saad_iqbal/mycred.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3UNKNOWN7

Vulnerabilities

Page 1 of 1
CVE-2026-27440MEDIUMCVSS 6.5≤ 2.9.7.62026-02-19
CVE-2026-27440 [MEDIUM] CWE-79 CVE-2026-27440: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred mycred allows Stored XSS.This issue affects myCred: from n/a through <= 2.9.7.6.
cvelistv5nvd
CVE-2026-24951MEDIUMCVSS 4.3≤ 2.9.7.32026-02-03
CVE-2026-24951 [MEDIUM] CWE-862 CVE-2026-24951: Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Config Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 2.9.7.3.
cvelistv5nvd
CVE-2025-54667UNKNOWN≤ 2.9.4.32025-08-14
CVE-2025-54667 CWE-367 CVE-2025-54667: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Saad Iqbal myCred mycred allows L Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Saad Iqbal myCred mycred allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions.This issue affects myCred: from n/a through <= 2.9.4.3.
cvelistv5nvd
CVE-2025-54668UNKNOWN≤ 2.9.4.32025-08-14
CVE-2025-54668 CWE-79 CVE-2025-54668: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred mycred allows Stored XSS.This issue affects myCred: from n/a through <= 2.9.4.3.
cvelistv5nvd
CVE-2025-49872UNKNOWN≤ 2.9.4.22025-06-17
CVE-2025-49872 CWE-862 CVE-2025-49872: Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Accessing Functionality Not P Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects myCred: from n/a through <= 2.9.4.2.
cvelistv5nvd
CVE-2025-49857UNKNOWN≤ 2.9.4.22025-06-17
CVE-2025-49857 CWE-862 CVE-2025-49857: Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Config Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 2.9.4.2.
cvelistv5nvd
CVE-2024-43214MEDIUMCVSS 5.3≤ 2.7.22024-08-26
CVE-2024-43214 [MEDIUM] CWE-862 CVE-2024-43214: Missing Authorization vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a Missing Authorization vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.
cvelistv5nvd
CVE-2024-43354UNKNOWN≤ 2.7.22024-08-19
CVE-2024-43354 CWE-502 CVE-2024-43354: Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCre Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.
cvelistv5nvd
CVE-2024-43353UNKNOWN≤ 2.7.22024-08-18
CVE-2024-43353 CWE-79 CVE-2024-43353: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.
cvelistv5nvd
CVE-2024-32711UNKNOWN≤ 2.6.32024-04-24
CVE-2024-32711 CWE-79 CVE-2024-32711: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.6.3.
cvelistv5nvd