Product
high
advisory
Prototype Pollution in cleverbrush Deep Library
1 CVECVE-2026-78654 is a prototype pollution vulnerability in the deepExtend function of the cleverbrush deep library (versions <= 4.4.0) that permits arbitrary modification of object prototype attributes.
framework +1
1c
high
threat
Shopper Framework Authorization Bypass in Multiple Livewire Admin Components
2 rules 1 TTPMultiple Livewire components in the Shopper framework admin panel allowed authenticated low-privilege users to bypass authorization and mutate data without the required permissions, leading to potential privilege escalation and cross-site scripting.
framework
authorization-bypass
privilege-escalation
xss
web-application
2r
1t