CVE-2026-84485 is a high-severity vulnerability in APITable through 1.13.0-beta.1 that exposes an internal organization loadOrSearch endpoint without authentication. This allows unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. The vulnerability has a CVSS score of 8.7 and is considered high severity. Affected deployments should prioritize verifying exposure and ensu [truncated]
CVE-2026-80208 is a high-severity vulnerability in APITable through 1.13.0-beta.1. The vulnerability allows unauthenticated clients to bypass the 30-day cooling-off period after a user deletion request, leading to permanent account deletion and data loss. This could result in significant data loss for APITable users if exploited. Defenders responsible for APITable instances, particularly those with expose [truncated]
CVE-2026-80207 is a medium-severity vulnerability in APITable through 1.13.0-beta.1. An unauthenticated attacker can create arbitrary notifications in apitable_player_notification against any user ID, which are stored with the system sender and rendered in the victim's inbox as legitimate system notifications. This vulnerability allows an attacker to persist notifications with arbitrary content, posing a [truncated]