CVE-2026-88939
— knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption
knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoin…
Remote
|
Authorization
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-88938
— knowns through 0.33.0 Path Traversal via code.find MCP tool
knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files anywhere on the host. Attackers can supply abso…
Remote
|
Path Traversal
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-88937
— knowns through 0.33.0 Path Traversal via Template Engine
knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Atta…
Remote
|
Path Traversal
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-88899
— knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory…
knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute f…
Remote
|
Path Traversal
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-88924
— Gvfs: gvfs-admin socket ownership race permits local root
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathn…
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-88898
— AppFlowy-Cloud 0.7.2 through 0.9.64 Missing Workspace Authorization on Bulk Publish Endpo…
AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' nam…
Remote
|
Authorization
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-88897
— Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String
Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can re…
Remote
|
Authentication
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-88008
— Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')…
Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token,…
Remote
|
Authentication
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTr…
Remote
|
Authentication
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-88006
— Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token …
Remote
|
Authentication
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-88005
— Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in v…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token w…
Remote
|
Authentication
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-88004
— Traefik entrypoint header-name sanitization bypassed via request trailers
Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.…
Remote
|
Misconfiguration
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-85310
— WordPress Groundhogg plugin <= 4.7.1 - Path Traversal vulnerability
import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.
Remote
|
Path Traversal
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-84821
— WordPress WP Fast Total Search plugin <= 1.82.284 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.
Remote
|
Authorization
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-84819
— WordPress WPAdverts plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.
Remote
|
Cross-Site Scripting
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-84816
— WordPress WPCS plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.
Remote
|
Cross-Site Scripting
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-81805
— WordPress SiteSkite plugin <= 2.1.5 - Privilege Escalation vulnerability
Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
Remote
|
Authorization
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-81804
— WordPress ZHBackup – Backup, Restore & Migration plugin <= 2.4.2 - Sensitive Data Exposur…
Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions.
Remote
|
Information Disclosure
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-81803
— WordPress RepairBuddy plugin <= 4.1224 - Remote Code Execution (RCE) vulnerability
Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.
Remote
|
Injection
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
CVE-2026-81801
— WordPress WP-Stateless plugin <= 4.4.1 - Settings Change vulnerability
Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.
Remote
|
Misconfiguration
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026
Sep 10, 2026