Robuta

https://idor.com/ טכנולוגיה ואנשים. יוצרים סביבה ארגונית בטוחה יותר | IDOR GOUP Mar 4, 2026 - יצירת סביבה ארגונית בטוחה בעזרת ייעוץ סייבר, פתרונות טכנולוגיה מובילים ומיקור חוץ והשמה של החברות בקבוצת עידור, בהתאמה מדויקת, באמון ושותפות. idorgoup https://idornext.co.il/ IDOR NEXT | השמה ומיקור חוץ להייטק, IT וסייבר Mar 22, 2026 - IDOR NEXT מחברת בין ארגונים לאנשי טכנולוגיה, IT וסייבר בהשמה ומיקור חוץ. גישה בוטיקית, התאמה מקצועית ותרבותית, וליווי אישי כחלק מקבוצת עידור. idornext https://portswigger.net/web-security/access-control/idor Insecure direct object references (IDOR) | Web Security Academy In this section, we will explain what insecure direct object references (IDOR) are and describe some common vulnerabilities. What are insecure direct object ... object referencesweb securityinsecuredirectidor https://en.idor.org/ IDOR – Instituto D'Or de Pesquisa e Ensino idorinstitutodepesquisaensino https://advisories.gitlab.com/composer/wwbn/avideo/CVE-2026-40907/ WWBN AVideo has an IDOR in Live Restreams list.json.php Exposes Other Users' Stream Keys and OAuth... CVE-2026-40907 WWBN AVideo has an IDOR in Live Restreams list.json.php Exposes Other Users' Stream Keys and OAuth Tokens: The endpoint... https://advisories.gitlab.com/composer/magento/community-edition/CVE-2021-21022/ Magento Insecure Direct Object Reference (IDOR) in the product module | GitLab Advisory Database... CVE-2021-21022 Magento Insecure Direct Object Reference (IDOR) in the product module: Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6... https://advisories.gitlab.com/composer/grumpydictator/firefly-iii/GHSA-5q8v-j673-m5v4/ Firefly III user API endpoints expose all users' information to any authenticated user (IDOR) |... GHSA-5q8v-j673-m5v4 Firefly III user API endpoints expose all users' information to any authenticated user (IDOR): The User management API endpoints (GET... https://advisories.gitlab.com/composer/moodle/moodle/CVE-2025-3647/ Moodle allows IDOR when accessing the cohorts report | GitLab Advisory Database (GLAD) CVE-2025-3647 Moodle allows IDOR when accessing the cohorts report: A flaw was discovered in Moodle. Additional checks were required to ensure that users can... the cohorts https://kathan19.gitbook.io/howtohunt/idor/idor IDOR | HowToHunt idor https://advisories.gitlab.com/pypi/label-studio/CVE-2026-22033/ Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile... CVE-2026-22033 Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field: A persistent stored... https://advisories.gitlab.com/composer/moodle/moodle/CVE-2024-48899/ Moodle IDOR when accessing list of course badges | GitLab Advisory Database (GLAD) CVE-2024-48899 Moodle IDOR when accessing list of course badges: A vulnerability was found in Moodle. Additional checks are required to ensure users can only... list of https://advisories.gitlab.com/npm/n8n/CVE-2026-42227/ n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure | GitLab Advisory... CVE-2026-42227 n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure: An authenticated user with a valid API key scoped to... https://advisories.gitlab.com/pypi/khoj/CVE-2025-69207/ Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning | GitLab Advisory Database (GLAD) CVE-2025-69207 Khoj has an IDOR in Notion OAuth Flow that Enables Index Poisoning: An IDOR in the Notion OAuth callback allows an attacker to hijack any user's... https://advisories.gitlab.com/composer/moodle/moodle/CVE-2025-3636/ Moodle allows IDOR in RSS block, which allows access to additional RSS feeds | GitLab Advisory... CVE-2025-3636 Moodle allows IDOR in RSS block, which allows access to additional RSS feeds: A flaw was found in Moodle. This vulnerability allows unauthorized... https://advisories.gitlab.com/composer/moodle/moodle/CVE-2025-26531/ Moodle has an IDOR in badges allows disabling of arbitrary badges | GitLab Advisory Database (GLAD) CVE-2025-26531 Moodle has an IDOR in badges allows disabling of arbitrary badges: Insufficient capability checks made it possible to disable badges a user does... https://advisories.gitlab.com/npm/payload/CVE-2026-25574/ payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments) | GitLab... CVE-2026-25574 payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments): A cross-collection Insecure Direct Object Reference... https://advisories.gitlab.com/pypi/open-webui/CVE-2024-7041/ open-webui Insecure Direct Object Reference (IDOR) vulnerability | GitLab Advisory Database (GLAD) CVE-2024-7041 open-webui Insecure Direct Object Reference (IDOR) vulnerability: An Insecure Direct Object Reference (IDOR) vulnerability exists in... open webuiobject reference https://advisories.gitlab.com/gem/spree_core/CVE-2026-22589/ Spree API has Unauthenticated IDOR - Guest Address | GitLab Advisory Database (GLAD) CVE-2026-22589 Spree API has Unauthenticated IDOR - Guest Address: An Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that... spreeapiidor https://advisories.gitlab.com/golang/github.com/zitadel/zitadel/CVE-2025-27507/ IDOR Vulnerabilities in ZITADEL's Admin API that Primarily Impact LDAP Configurations | GitLab... CVE-2025-27507 IDOR Vulnerabilities in ZITADEL's Admin API that Primarily Impact LDAP Configurations: ZITADEL's Admin API contains Insecure Direct Object... https://www.idordiamonds.com/ Idor Diamonds Inc. idordiamondsinc https://taxschool.illinois.edu/post/idor-to-abate-late-estimated-payment-penalties-for-pte-tax/ IDOR to Abate Late Estimated Payment Penalties for PTE Tax - U of I Tax School Jan 30, 2026 - Great news for entities who made late 4th-quarter estimated PTE tax payments! Learn how the IDOR is offering penalty abatement for eligible filers. https://advisories.gitlab.com/npm/agents/CVE-2026-1664/ Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email Routing |... CVE-2026-1664 Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email Routing: An Insecure Direct Object Reference (CWE-639)... https://advisories.gitlab.com/composer/moodle/moodle/CVE-2024-48901/ moodle: IDOR when fetching report schedules | GitLab Advisory Database (GLAD) CVE-2024-48901 moodle: IDOR when fetching report schedules: A vulnerability was found in Moodle. Additional checks are required to ensure users can only access... moodleidorfetchingreportschedules https://advisories.gitlab.com/composer/craftcms/cms/CVE-2026-28782/ Craft CMS has Permission Bypass and IDOR in Duplicate Entry Action | GitLab Advisory Database (GLAD) CVE-2026-28782 Craft CMS has Permission Bypass and IDOR in Duplicate Entry Action: The "Duplicate" entry action does not properly verify if the user has... https://advisories.gitlab.com/composer/getgrav/grav/CVE-2025-66306/ Grav vulnerable to Information Disclosure via IDOR in Grav Admin Panel | GitLab Advisory Database... CVE-2025-66306 Grav vulnerable to Information Disclosure via IDOR in Grav Admin Panel: An IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS... https://advisories.gitlab.com/composer/jweiland/events2/CVE-2024-38874/ events2 TYPO3 extension insecure direct object reference (IDOR) vulnerability | GitLab Advisory... CVE-2024-38874 events2 TYPO3 extension insecure direct object reference (IDOR) vulnerability: An issue was discovered in the events2 (aka Events 2) extension... object referenceextensioninsecuredirect https://adisinsight.springer.com/drugs/800081113?error=cookies_not_supported&code=257e3263-21a8-44c4-8ca5-516f3114011c IDOR 1142 0810 - AdisInsight IDOR 1142 0810 is a synthetic glycan vaccine being developed by Idorsia pharmaceuticals for the treatment of Klebsiella pneumonia infection. Preclinical idoradisinsight https://advisories.gitlab.com/maven/io.dataease/dataease-plugin-common/CVE-2023-32310/ DataEase API interface has IDOR vulnerability | GitLab Advisory Database (GLAD) CVE-2023-32310 DataEase API interface has IDOR vulnerability: DataEase is an open source data visualization and analysis tool. The API interface for DataEase... api interfacedataeaseidorvulnerabilitygitlab https://advisories.gitlab.com/composer/wwbn/avideo/GHSA-gpgp-w4x2-h3h7/ WWBN AVideo has an IDOR in Live Restreams list.json.php Exposes Other Users' Stream Keys and OAuth... GHSA-gpgp-w4x2-h3h7 WWBN AVideo has an IDOR in Live Restreams list.json.php Exposes Other Users' Stream Keys and OAuth Tokens: The endpoint... https://advisories.gitlab.com/golang/github.com/juju/juju/CVE-2026-32694/ Juju affected by Confused Deputy IDOR attack via Predictable user specified ID in Juju Secrets |... CVE-2026-32694 Juju affected by Confused Deputy IDOR attack via Predictable user specified ID in Juju Secrets: Predictable secret ID and lack of secret origin... https://advisories.gitlab.com/golang/github.com/filebrowser/filebrowser/CVE-2025-64523/ File Browser is Vulnerable to Insecure Direct Object Reference (IDOR) in Share Deletion Function |... CVE-2025-64523 File Browser is Vulnerable to Insecure Direct Object Reference (IDOR) in Share Deletion Function: It has been found an Insecure Direct Object...