Broken Access Control Moderate I-Educar Security WebApp BOLA CVE-2025-11047 Broken Access Control (BOLA)
XSS File Upload Bypass Moderate NovoSGA Security WebApp CVE-2025-10909 XSS Injection via SVG File Upload Bypass