π¨ CVE-2026-19044
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - LeeSinLiang/godot-mcp: A Model Context Protocol (MCP) server that enables AI assistants to interact with the Godot gameβ¦
A Model Context Protocol (MCP) server that enables AI assistants to interact with the Godot game engine. - LeeSinLiang/godot-mcp
π¨ CVE-2026-19045
A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command injection. It is possible to launch the attack on the local host. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command injection. It is possible to launch the attack on the local host. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - NocteDefensor/LudusMCP
Contribute to NocteDefensor/LudusMCP development by creating an account on GitHub.
π¨ CVE-2026-25403
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
π@cveNotify
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Ultimate Store Kit Elementor Addons Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28005
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
π@cveNotify
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
π@cveNotify
Patchstack
Privilege Escalation in WordPress Kadence WooCommerce Email Designer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28082
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress JetEngine Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28139
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
π@cveNotify
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
π@cveNotify
Patchstack
PHP Object Injection in WordPress Ajax Search Lite Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28140
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
π@cveNotify
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress JetFormBuilder Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28141
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress NextGEN Gallery Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28143
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Forminator Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28146
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
π@cveNotify
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
π@cveNotify
Patchstack
Arbitrary File Download in WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28172
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
π@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
π@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress Tracking Code Manager Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28177
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Popup Maker Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28178
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
π@cveNotify
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Powerkit Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28179
Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
π@cveNotify
Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress FiboSearch Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28180
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
π@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
π@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Mercado Pago payments for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28183
Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions.
π@cveNotify
Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions.
π@cveNotify
Patchstack
Privilege Escalation in WordPress PublishPress Capabilities Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-32327
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
π@cveNotify
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function.
Users are recommended to upgrade to version 1.6.4, which fixes this issue.
π@cveNotify
π¨ CVE-2026-32469
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
π@cveNotify
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
π@cveNotify
Patchstack
Bypass Vulnerability in WordPress CAPTCHA 4WP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-32548
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
π@cveNotify
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress SureCart Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-34191
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
π@cveNotify
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
π@cveNotify