Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.1 MEDIUM
CVE-2026-77081 — n8n before 1.123.69 Allowed-Domains Bypass via GraphQL Node

n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. When the node's Authentication parameter is set to expression mode, every authenti…

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.7 HIGH
CVE-2026-77080 — n8n before 1.123.69 Arbitrary File Read and Write via Snowflake

n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which passes free-form Execute Query input, including cl…

Remote | Path Traversal
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.4 HIGH
CVE-2026-77079 — n8n before 2.34.1 Authorization Bypass via Custom Role Deletion

n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project role with a reassignment target, the code validat…

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.2 HIGH
CVE-2026-77077 — n8n before 1.123.69 Remote Code Execution via EventEmitter Prototype Pollution

n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runner's prototype-freezing routine covers globalThis functions but not internal module constr…

Remote | Misconfiguration
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.1 HIGH
CVE-2026-77076 — n8n before 1.123.69 Credential Leak via GraphQL Node Error

n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQL node. When a GraphQL request fails at the connection level, the node re-throws the unde…

Remote | Information Disclosure
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.4 HIGH
CVE-2026-77075 — n8n before 1.123.69 Expression Injection via Resource Locator

n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vulnerability in resource-locator field link preview rendering. The editor spliced the field's stored …

Remote | Injection
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.0 MEDIUM
CVE-2026-77074 — n8n before 1.123.69 SSRF via Edit Image Node

n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation that allows authenticated users to inject MVG primitives. Attackers can c…

Remote | Server-Side Request Forgery
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.3 MEDIUM
CVE-2026-77073 — n8n before 2.34.1 Cross-Project Credential Access via MCP

n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an expression. Attackers with a valid MCP Bearer API key…

Remote | Authentication
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.4 HIGH
CVE-2026-77072 — n8n before 1.123.69 Stored XSS via Form Completion Page

n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the Form node's completion page. The completion page applied its sandboxing Content-Security-Policy onl…

Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.1 HIGH
CVE-2026-77071 — n8n before 1.123.69 PostgREST Filter Injection via Supabase

n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update operations, which built filter queries by concatena…

Remote | Injection
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.1 HIGH
CVE-2026-77070 — n8n before 1.123.69 NoSQL Injection via MongoDB Node

n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate operations, which parse the Query parameter as JSON after expression…

Remote | Injection
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
2.3 LOW
CVE-2026-77069 — n8n before 1.123.69 SSRF Protection Bypass via OAuth2

n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential authorization-code-to-access-token exchange. While OAuth2 discovery and dynamic-client-registration…

Remote | Server-Side Request Forgery
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.7 HIGH
CVE-2026-77068 — n8n before 2.34.1 Remote Code Execution via Path Traversal

n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP node-schema loading. The loader derives a node's sche…

Remote | Path Traversal
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.5 HIGH
CVE-2026-74021 — WordPress Chaplin theme <= 2.6.8 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.5 HIGH
CVE-2026-74020 — WordPress Koji theme <= 2.2.1 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Koji <= 2.2.1 versions.

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.1 HIGH
CVE-2026-74019 — WordPress EPROLO Dropshipping plugin <= 2.4.2 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.9 CRITICAL
CVE-2026-74018 — WordPress Warehouse Cargo theme <= 2.6.9 - Arbitrary File Upload vulnerability

Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.

Remote | Misconfiguration
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.9 CRITICAL
CVE-2026-74016 — WordPress Smart Cleaning theme <= 4.8.6 - Arbitrary File Upload vulnerability

Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.

Remote | Misconfiguration
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.9 CRITICAL
CVE-2026-74014 — WordPress IT Residence theme <= 3.2.1 - Arbitrary File Upload vulnerability

Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.

Remote | Misconfiguration
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.5 HIGH
CVE-2026-74013 — WordPress eShipper Commerce plugin <= 2.16.13 - SQL Injection vulnerability

Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.

Remote | Injection
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
Showing 20 of 12715 Results