π¨ CVE-2026-19040
A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/services/dcrClients.ts. Executing a manipulation can lead to server-side request forgery. The attack may be performed from remote. Upgrading to version 1.11.10 is sufficient to fix this issue. This patch is called f068ab4ad6f0907ac7001b995588c2673f11a755. You should upgrade the affected component.
π@cveNotify
A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/services/dcrClients.ts. Executing a manipulation can lead to server-side request forgery. The attack may be performed from remote. Upgrading to version 1.11.10 is sufficient to fix this issue. This patch is called f068ab4ad6f0907ac7001b995588c2673f11a755. You should upgrade the affected component.
π@cveNotify
GitHub
GitHub - MissionSquad/mcp-api: MCP Proxy Server. Streaming. Node/Python. OAuth w/ DCR.
MCP Proxy Server. Streaming. Node/Python. OAuth w/ DCR. - MissionSquad/mcp-api
π¨ CVE-2026-5134
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection.
This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection.
This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
siberguvenlik.gov.tr
T.C. Siber GΓΌvenlik BaΕkanlΔ±ΔΔ±
TΓΌrkiye Cumhuriyeti CumhurbaΕkanlΔ±ΔΔ± Siber GΓΌvenlik BaΕkanlΔ±ΔΔ± resmi web sitesi.
π¨ CVE-2026-64993
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.
π@cveNotify
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.
π@cveNotify
π¨ CVE-2026-19044
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - LeeSinLiang/godot-mcp: A Model Context Protocol (MCP) server that enables AI assistants to interact with the Godot gameβ¦
A Model Context Protocol (MCP) server that enables AI assistants to interact with the Godot game engine. - LeeSinLiang/godot-mcp
π¨ CVE-2026-28005
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
π@cveNotify
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
π@cveNotify
Patchstack
Privilege Escalation in WordPress Kadence WooCommerce Email Designer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28139
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
π@cveNotify
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
π@cveNotify
Patchstack
PHP Object Injection in WordPress Ajax Search Lite Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28141
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress NextGEN Gallery Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28169
Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
π@cveNotify
Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
π@cveNotify
Patchstack
Sensitive Data Exposure in WordPress YITH WooCommerce Zoom Magnifier Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28177
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Popup Maker Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28180
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
π@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
π@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Mercado Pago payments for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-32469
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
π@cveNotify
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
π@cveNotify
Patchstack
Bypass Vulnerability in WordPress CAPTCHA 4WP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-53975
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.
π@cveNotify
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.
π@cveNotify
GitHub
GitHub - openchamber/openchamber: Agentic Development Environment based on OpenCode AI agent
Agentic Development Environment based on OpenCode AI agent - openchamber/openchamber
π¨ CVE-2026-61961
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress EmbedPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-61964
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Ninja Tables Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65504
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
π@cveNotify
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress BOX NOW Delivery Croatia Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65508
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
π@cveNotify
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
π@cveNotify
Patchstack
SQL Injection in WordPress Simply Schedule Appointments Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65515
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress AffiliateWP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65520
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
π@cveNotify
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
π@cveNotify
Patchstack
SQL Injection in WordPress WP OAuth Server Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65542
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
π@cveNotify
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
π@cveNotify
Patchstack
Broken Authentication in WordPress Super Socializer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65544
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Super Socializer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.