๐Ÿ” CVE Alert

CVE-2026-10284

MEDIUM 5.4

DevaslanPHP project-management Livewire ViewTicket.php doDeleteComment improper authorization

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
13th

A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the function editComment/doDeleteComment of the file app/Filament/Resources/TicketResource/Pages/ViewTicket.php of the component Livewire Handler. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet.

CWE CWE-285 CWE-266
Vendor devaslanphp
Product project-management
Published Jun 1, 2026
Last Updated Jun 3, 2026
Stay Ahead of the Next One

Get instant alerts for devaslanphp project-management

Be the first to know when new medium vulnerabilities affecting devaslanphp project-management are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:X/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

DevaslanPHP / project-management
2.0.0-beta1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/367577 vuldb.com: https://vuldb.com/vuln/367577/cti vuldb.com: https://vuldb.com/cve/CVE-2026-10284 vuldb.com: https://vuldb.com/submit/825473 github.com: https://github.com/devaslanphp/project-management/issues/140 github.com: https://github.com/devaslanphp/project-management/

Credits

๐Ÿ” Mitchell45 (VulDB User) VulDB CNA Team