Skip to content

Known CVE

Gorse < 0.5.10 - Unauthenticated Database Dump

Gorse < 0.5.10 contains an authentication bypass caused by empty admin_api_key in /api/dump and /api/restore endpoints, letting unauthenticated remote attackers access and modify protected data, exploit requires default empty admin_api_key configuration.

CVE-2026-56782

Critical2026CVSS 9.8CWE-306

cve2026 · gorse · unauth · exposure · misconfig

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website