π¨ CVE-2026-19044
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - LeeSinLiang/godot-mcp: A Model Context Protocol (MCP) server that enables AI assistants to interact with the Godot gameβ¦
A Model Context Protocol (MCP) server that enables AI assistants to interact with the Godot game engine. - LeeSinLiang/godot-mcp
π¨ CVE-2026-28005
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
π@cveNotify
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
π@cveNotify
Patchstack
Privilege Escalation in WordPress Kadence WooCommerce Email Designer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28139
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
π@cveNotify
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
π@cveNotify
Patchstack
PHP Object Injection in WordPress Ajax Search Lite Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28141
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress NextGEN Gallery Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28169
Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
π@cveNotify
Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
π@cveNotify
Patchstack
Sensitive Data Exposure in WordPress YITH WooCommerce Zoom Magnifier Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28177
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Popup Maker Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-28180
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
π@cveNotify
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
π@cveNotify
Patchstack
Insecure Direct Object References (IDOR) in WordPress Mercado Pago payments for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-32469
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
π@cveNotify
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
π@cveNotify
Patchstack
Bypass Vulnerability in WordPress CAPTCHA 4WP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-53975
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.
π@cveNotify
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.
π@cveNotify
GitHub
GitHub - openchamber/openchamber: Agentic Development Environment based on OpenCode AI agent
Agentic Development Environment based on OpenCode AI agent - openchamber/openchamber
π¨ CVE-2026-61961
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress EmbedPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-61964
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Ninja Tables Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65504
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
π@cveNotify
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress BOX NOW Delivery Croatia Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65508
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
π@cveNotify
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
π@cveNotify
Patchstack
SQL Injection in WordPress Simply Schedule Appointments Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65515
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress AffiliateWP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65520
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
π@cveNotify
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
π@cveNotify
Patchstack
SQL Injection in WordPress WP OAuth Server Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65542
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
π@cveNotify
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
π@cveNotify
Patchstack
Broken Authentication in WordPress Super Socializer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65544
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Super Socializer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65549
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
π@cveNotify
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
π@cveNotify
Patchstack
PHP Object Injection in WordPress Jeg Kit for Elementor Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65554
Subscriber Broken Access Control in AnsPress β Question and answer 4.4.4 versions.
π@cveNotify
Subscriber Broken Access Control in AnsPress β Question and answer 4.4.4 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress AnsPress β Question and answer Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
π¨ CVE-2026-65559
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
π@cveNotify
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
π@cveNotify
Patchstack
Privilege Escalation in WordPress Order Delivery Date for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.