| CVE ID | CVSS Score | Severity | Description |
|---|---|---|---|
| CVE-2026-81823 | 5.3 | medium |
The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.
|
| CVE-2026-81822 | 8.4 | high |
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users' app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user.
|
| CVE-2026-81821 | 8.4 | high |
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.
|
| CVE-2026-81824 | 4.7 | medium |
The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.
|