CVE-2026-100303

CVE-2026-100303 published: TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, modify, or delete themes and theme categories affecting forms owned by other users.

View full NVD advisory → ← Back to CVE watch