PatchSiren

phoenixthrush CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM phoenixthrush CVE published 2026-10-10

CVE-2026-108580

AniWorld Downloader before 5.3.0 contains an improper restriction of authentication attempts vulnerability in the WebUI /login POST handler. This allows unauthenticated attackers to guess passwords without throttling, potentially leading to unauthorized access. Defenders should assess exposure and prioritize upgrading to version 5.3.0 or later to mitigate this vulnerability. The vulnerability impacts defe [truncated]