CVE-2026-89023
ThemeAtelier Domain For Sale — Missing Authorization via REST API
Unauthenticated attackers could access and manipulate protected REST API resources in Domain For Sale versions before 3.5.2, including retrieving stored offers, deleting offers by numeric identifier, and accessing dashboard statistics containing sensitive bidder and business data.
