CVE-2025-54598
27.08.2025, 16:15
The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete all notifications via the /notifications/delete/ URI.
Vendor | Product | Version |
---|---|---|
bevy | bevy | 𝑥 ≤ 2025-06-24 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration