PT-2026-70796 · Unknown · Ishankportfolio

CVE-2026-48771

·

Published

2026-08-11

·

Updated

2026-08-13

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions ishankportfolio versions prior to 1.0.1
Description Contact form submissions may be exposed due to improperly secured client-side database configuration and insufficient access control policies. Applications using publicly exposed database credentials or permissive database rules may allow unauthorized users to read, modify, or abuse stored form submission data. This could impact personally identifiable information (PII), such as names, email addresses, phone numbers, and messages.
Recommendations Update to version 1.0.1. Disable public read/write database access. Rotate exposed API keys. Restrict database policies to authenticated requests only. Move sensitive operations to secure backend or serverless functions. Monitor database activity logs for suspicious access.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48771

Affected Products

Ishankportfolio