CVE-2026-64822 is a user enumeration vulnerability in djangoSIGE through 1.10 (commit a6fe7e8). The vulnerability allows unauthenticated attackers to identify valid accounts by observing distinct error messages returned by the password reset endpoint. Attackers can submit arbitrary usernames or email addresses to the POST login/esqueceu/ endpoint and distinguish between existing and non-existing accounts [truncated]
CVE-2026-64821: djangoSIGE Cross-Site Request Forgery Vulnerability. The CVE record was published on 2026-07-21T21:16:53.497Z and has not been modified since then. The NVD entry is currently 5.3 MEDIUM. This vulnerability affects djangoSIGE through version 1.10, allowing unauthenticated attackers to cancel sales or purchase orders on behalf of authenticated users due to improper implementation of order-ca [truncated]