
CVE@CVEnew
CVE-2026-92462 yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete … https://www.cve.org/CVERecord?id=CVE-2026-92462
00000591
58.1K followersView on X
