Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-56228 — Capgo - Denial of Service via Improper Password Policy Length Validation

Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated organization administrator can set an extremely larg…

Remote | Authentication
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
5.4 MEDIUM
CVE-2026-56227 — Capgo - Server-Side Request Forgery via Webhook URL Validation

Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. Organization admins can configure webhooks pointing t…

Remote | Server-Side Request Forgery
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
6.9 MEDIUM
CVE-2026-56218 — Capgo - EXIF Metadata Exposure via Image Upload

Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing information disclosure. Attackers can download uploaded images and extract precise lat…

Remote | Information Disclosure
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
6.1 MEDIUM
CVE-2025-71331 — Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows

Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent functions. An attacker can inject malicious JavaScrip…

flowise | Remote | Cross-Site Scripting
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
3.1 LOW
CVE-2026-56325 — Capgo - App ID Confusion via ILIKE Wildcard in Preview Subdomain Lookup

Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain resolver, allowing underscore characters in app_id to act as SQL wildcards. Atta…

Remote | Injection
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
2.3 LOW
CVE-2026-56317 — Nuxt - Cross-Site Scripting via NoScript Component Slot Content

Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML without escaping. Attackers can inje…

nuxt | Remote | Cross-Site Scripting
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
9.8 CRITICAL
CVE-2024-58351 — Flowise - Remote Code Execution via overrideConfig Parameter

Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the frontend web integration and the backend Prediction A…

flowise | Remote | Injection
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
9.8 CRITICAL
CVE-2022-50972 — WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php

WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send…

woocommerce | Remote | Injection
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
8.7 HIGH
CVE-2020-37255 — WordPress Time Capsule Plugin 1.21.16 Authentication Bypass

WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by sending a crafted POST request with the IW…

Remote | Authentication
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
9.8 CRITICAL
CVE-2019-25763 — WordPress Ultimate Addons for Beaver Builder 1.2.4.1 Authentication Bypass

WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functi…

Remote | Authentication
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
5.9 MEDIUM
CVE-2026-12673 — Liquidfiles Broken Access Control Privilege Escalation

Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a secondary domain to a Sysadmin by modifying a group in th…

liquidfiles | Remote | Authorization
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
10.0 CRITICAL
CVE-2026-48908 — Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for…

A vulnerability in the SP Page Builder for Joomla allows the upload of arbitrary files for unauthenticated users, ultimately resulting in PHP code upload and execution.

Remote | Misconfiguration
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
10.0 CRITICAL
CVE-2026-48939 — Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla …

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

Remote | Misconfiguration
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
9.5 CRITICAL
CVE-2026-48909 — Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla <…

SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.

Remote | Misconfiguration
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
6.5 MEDIUM
CVE-2026-12119 — Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitra…

The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the 'frontmanage' shortcode attribute in all versions up to, and includ…

simple-file-list | Remote | Authorization
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
7.5 HIGH
CVE-2026-11911 — Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in…

The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile function in all versions up to, and including, 6.3.…

simple-file-list | Remote | Path Traversal
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
7.5 HIGH
CVE-2026-11912 — Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification vi…

The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for…

simple-file-list | Remote | Authorization
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
8.1 HIGH
CVE-2026-9843 — Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrar…

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versi…

Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
0.0 NA
CVE-2026-9265 — Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_att…

Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRING ASN.1 attribute value into a heap buffer sized …

| Memory Corruption
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
8.8 HIGH
CVE-2026-56216 — Capgo - Scope Escalation via API Key Creation in /functions/v1/apikey

Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows app-limited API keys to mint unrestricted keys by setting empty limits. Attackers…

Remote | Authorization
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
Showing 20 of 7440 Results