{"id":"CVE-2025-11580","aliases":["GHSA-87xj-ghmc-c3xq"],"url":"https://o3.security/vulnerability/CVE-2025-11580","summary":"PowerJob list authorization","details":"A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This manipulation causes missing authorization. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.","published":"2025-10-10T18:02:05.673Z","modified":"2026-08-12T03:51:18.862579944Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"tech.powerjob:powerjob","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/PowerJob/PowerJob/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11580.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-11580"},{"type":"ADVISORY","url":"https://vuldb.com/?id.327902"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.662446"},{"type":"REPORT","url":"https://github.com/PowerJob/PowerJob/issues/1127"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.327902"},{"type":"PACKAGE","url":"https://github.com/PowerJob/PowerJob"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:18.862579944Z"}}