In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. guest role users can self-register even when the admin does not allow it. This happens due to front-end restriction only.
{
"nvd_published_at": "2021-11-02T07:15:00Z",
"cwe_ids": [
"CWE-285",
"CWE-669",
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed_at": "2021-11-03T14:44:37Z",
"github_reviewed": true
}