PatchSiren

Attendize CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Attendize CVE published 2026-08-11

CVE-2026-72547

The CVE-2026-72547 record indicates an insecure direct object reference vulnerability in Attendize through commit 9289acb. This vulnerability allows authenticated event organisers to bulk import attendees into events belonging to other accounts without verifying ownership. The postImportAttendee endpoint is particularly susceptible to exploitation, enabling attackers to inject bulk attendee data into any [truncated]

HIGH Attendize CVE published 2026-08-11

CVE-2026-72546

An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to inject attendees and orders into events belonging to other accounts via the postInviteAttendee endpoint. The endpoint loads the target event by ID without scoping the query to the authenticated organiser account. This vulnerability enables attackers to modify event data and fin [truncated]

HIGH Attendize CVE published 2026-08-10

CVE-2026-72690

The CVE-2026-72690 record details an improper authorization vulnerability in Attendize, a software used for event management. This vulnerability, tracked as CVE-2026-72690, allows an authenticated remote attacker to inject persistent mandatory survey questions into another organizer's events. The issue arises from the postCreateEventQuestion method loading the target event without tenant-isolation scope, [truncated]