π¨ CVE-2026-19038
A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function screenshotElement of the file src/index.ts of the component screenshot_element Tool. Such manipulation of the argument output_name leads to path traversal. The attack can be executed remotely. Upgrading to version 1.1.1 is capable of addressing this issue. The name of the patch is 1102172c9adec4a619e241efd6bfb74f5b1f4332. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
π@cveNotify
A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function screenshotElement of the file src/index.ts of the component screenshot_element Tool. Such manipulation of the argument output_name leads to path traversal. The attack can be executed remotely. Upgrading to version 1.1.1 is capable of addressing this issue. The name of the patch is 1102172c9adec4a619e241efd6bfb74f5b1f4332. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
π@cveNotify
GitHub
GitHub - MonomythDevelopment/la-forge-mcp: Visual CSS debugging for AI coding assistants β an MCP server for pixel-perfect screenshotβ¦
Visual CSS debugging for AI coding assistants β an MCP server for pixel-perfect screenshot comparison, computed-style extraction, and CSS rule-chain analysis. - MonomythDevelopment/la-forge-mcp
π¨ CVE-2026-19039
A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted is the function ssh_exec of the file src/index.ts of the component SSH Command Handler. Performing a manipulation of the argument host/username results in command injection. The attack requires a local approach. The actual existence of this vulnerability is currently in question. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project maintainer explains: "The intended threat model is that this MCP server is a local/trusted tool for an agent to execute commands over SSH, so callers already have meaningful execution capability through the exposed shell."
π@cveNotify
A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted is the function ssh_exec of the file src/index.ts of the component SSH Command Handler. Performing a manipulation of the argument host/username results in command injection. The attack requires a local approach. The actual existence of this vulnerability is currently in question. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project maintainer explains: "The intended threat model is that this MCP server is a local/trusted tool for an agent to execute commands over SSH, so callers already have meaningful execution capability through the exposed shell."
π@cveNotify
GitHub
Local Command Injection Vulnerability in KinoThe-Kafkaesque/ssh-mcp-server Β· Issue #3 Β· KinoThe-Kafkaesque/ssh-mcp-server
Local Command Injection via SSH Command Construction Summary I found a local command injection issue in KinoThe-Kafkaesque/ssh-mcp-server. In src/index.ts, the ssh_exec handler constructs a local s...
π¨ CVE-2026-65551
Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Breakdance: from n/a before 2.7.
π@cveNotify
Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Breakdance: from n/a before 2.7.
π@cveNotify
Patchstack
Broken Access Control in WordPress Breakdance Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-70556
Hubzilla 11.2.1 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint handled by Zotlabs\Module\Authorize::post() that allows unauthenticated attackers to register arbitrary OAuth2 applications under an authenticated user's account by submitting a cross-origin POST request without CSRF token or Origin/Referer validation. Attackers can craft a malicious HTML form that autosubmits attacker-chosen OAuth2 parameters including client_id, client_secret, redirect_uri, and scope to silently register a persistent OAuth2 application, enabling interception of future OAuth2 authorization codes when the victim later authenticates against the attacker-controlled client.
π@cveNotify
Hubzilla 11.2.1 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint handled by Zotlabs\Module\Authorize::post() that allows unauthenticated attackers to register arbitrary OAuth2 applications under an authenticated user's account by submitting a cross-origin POST request without CSRF token or Origin/Referer validation. Attackers can craft a malicious HTML form that autosubmits attacker-chosen OAuth2 parameters including client_id, client_secret, redirect_uri, and scope to silently register a persistent OAuth2 application, enabling interception of future OAuth2 authorization codes when the victim later authenticates against the attacker-controlled client.
π@cveNotify
GitLab
hubzilla / core Β· GitLab
build community websites that can interact with one another
π¨ CVE-2026-12605
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.
π@cveNotify
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.
π@cveNotify
GitLab
CVE reservation request for GlassFish project report #445: Critical CSRF + SSRF in admingui DownloadServlet leaks admin gfresttokenβ¦
CVE Reservation Request For the
π¨ CVE-2026-64993
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.
π@cveNotify
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.
π@cveNotify
π¨ CVE-2025-49506
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
π@cveNotify
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
π@cveNotify
π¨ CVE-2026-15246
The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user such as a Subscriber to obtain paid membership packages without paying.
π@cveNotify
The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user such as a Subscriber to obtain paid membership packages without paying.
π@cveNotify
WPScan
RealHomes Memberships < 3.1.0 - Subscriber+ Membership Payment Bypass
See details on RealHomes Memberships < 3.1.0 - Subscriber+ Membership Payment Bypass CVE 2026-15246. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-19044
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - LeeSinLiang/godot-mcp: A Model Context Protocol (MCP) server that enables AI assistants to interact with the Godot gameβ¦
A Model Context Protocol (MCP) server that enables AI assistants to interact with the Godot game engine. - LeeSinLiang/godot-mcp
π¨ CVE-2026-19045
A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command injection. It is possible to launch the attack on the local host. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command injection. It is possible to launch the attack on the local host. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - NocteDefensor/LudusMCP
Contribute to NocteDefensor/LudusMCP development by creating an account on GitHub.
π¨ CVE-2026-25403
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
π@cveNotify
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Ultimate Store Kit Elementor Addons Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28005
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
π@cveNotify
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
π@cveNotify
Patchstack
Privilege Escalation in WordPress Kadence WooCommerce Email Designer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28082
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress JetEngine Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28139
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
π@cveNotify
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
π@cveNotify
Patchstack
PHP Object Injection in WordPress Ajax Search Lite Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28140
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
π@cveNotify
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress JetFormBuilder Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28141
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress NextGEN Gallery Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28143
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Forminator Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28146
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
π@cveNotify
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
π@cveNotify
Patchstack
Arbitrary File Download in WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28172
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
π@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
π@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Tracking Code Manager Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28177
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Popup Maker Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.