CRITICAL9.6CVE-2026-55518Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
from 0, < 3.32.1
HIGH8.8CVE-2026-42205Avo: Broken Access Control Through Unauthorized Execution of Arbitrary Action Classes Across Resources
from 0, < 3.31.2
HIGH8.3CVE-2023-34102avo possible unsafe reflection / partial DoS vulnerability
from 0, < 2.33.3
HIGH7.3avo vulnerable to stored cross-site scripting (XSS) in key_value field
>= 3.0.0.beta1, < 3.2.4
HIGH7.3avo vulnerable to Stored XSS (Cross Site Scripting) in html content based fields
from 0, < 2.33.3
MEDIUM6.5Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy
>= 2.28.0, < 3.32.0
MEDIUM6.5Cross-site scripting (XSS) in Action messages on Avo