Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Candy

#27672of 56,326
9.8Total CVSS
Vulnerabilities · 1
PT-2025-39877
9.8
2025-09-29
Unknown · Thrivex Blogging Framework · CVE-2025-57266
**Name of the Vulnerable Software and Affected Versions** ThriveX Blogging Framework versions 2.5.9 through 3.1.3 **Description** An issue exists in the `AssistantController.java` file that allows unauthenticated attackers to obtain sensitive information, such as API Keys. The `/api/assistant/list` API endpoint is affected. The issue allows gaining access to sensitive information. **Recommendations** Update ThriveX Blogging Framework to a version later than 3.1.3.