๐จ CVE-2026-28569
Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress SSL Zen Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-28571
Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.
๐@cveNotify
Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress FormyChat Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-32463
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
๐@cveNotify
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
๐@cveNotify
Patchstack
Arbitrary File Upload in WordPress Sync Post With Other Site Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-32465
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
๐@cveNotify
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
๐@cveNotify
Patchstack
PHP Object Injection in WordPress Essential Real Estate Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-32468
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
๐@cveNotify
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
๐@cveNotify
Patchstack
undefined in undefined undefined undefined
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-18534
ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk.
๐@cveNotify
ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk.
๐@cveNotify
arc.net
Security Bulletin
Experience a calmer, more personal internet in this browser designed for you. Let go of the clicks, the clutter, the distractions.
๐จ CVE-2026-32470
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
๐@cveNotify
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
๐@cveNotify
Patchstack
PHP Object Injection in WordPress FundEngine Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-32472
Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.
๐@cveNotify
๐จ CVE-2026-32481
Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
๐@cveNotify
Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress Ezoic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-32547
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress BP Better Messages Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-32549
Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
๐@cveNotify
Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress ThumbPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-32553
Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.
๐@cveNotify
Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.
๐@cveNotify
Patchstack
Server Side Request Forgery (SSRF) in WordPress OttoKit Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-45733
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and apps/client/src/services/note_autocomplete.ts, allowing a stored payload to execute automatically when a victim opens a new tab or uses Ctrl+J and, because Electron enables nodeIntegration and disables contextIsolation, run operating-system commands as the victim. This issue is fixed in version 0.103.0.
๐@cveNotify
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and apps/client/src/services/note_autocomplete.ts, allowing a stored payload to execute automatically when a victim opens a new tab or uses Ctrl+J and, because Electron enables nodeIntegration and disables contextIsolation, run operating-system commands as the victim. This issue is fixed in version 0.103.0.
๐@cveNotify
GitHub
fix(client): sanitize icon classes ยท TriliumNext/Trilium@c069394
Build your personal knowledge base with Trilium Notes - fix(client): sanitize icon classes ยท TriliumNext/Trilium@c069394
๐จ CVE-2026-48798
SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the requested local directory without containment validation, allowing a malicious, compromised, or man-in-the-middle server to use ../ sequences or absolute paths to create or overwrite files anywhere writable by the client process. This issue is fixed in version 2026.0.0.
๐@cveNotify
SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the requested local directory without containment validation, allowing a malicious, compromised, or man-in-the-middle server to use ../ sequences or absolute paths to create or overwrite files anywhere writable by the client process. This issue is fixed in version 2026.0.0.
๐@cveNotify
GitHub
Reject unsafe server-supplied names in SCP recursive download ยท sshnet/SSH.NET@600be0d
A malicious or compromised SCP server could return file or directory names containing
path separators, drive qualifiers, or parent-directory references.
ScpClient.Download(string, DirectoryInfo) co...
path separators, drive qualifiers, or parent-directory references.
ScpClient.Download(string, DirectoryInfo) co...
๐จ CVE-2026-50138
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to `golang.org/x/net/webdav.Handler` with no equivalent guard, so an authenticated WebDAV client can `PUT`, `DELETE`, `MKCOL`, `MOVE`, and `COPY` despite the operator's stated intent. Version 2.1.0 patches the issue.
๐@cveNotify
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to `golang.org/x/net/webdav.Handler` with no equivalent guard, so an authenticated WebDAV client can `PUT`, `DELETE`, `MKCOL`, `MOVE`, and `COPY` despite the operator's stated intent. Version 2.1.0 patches the issue.
๐@cveNotify
GitHub
WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags
# WebDAV listener ignores `--read-only`, `--upload-only`, and `--no-delete` mode flags
**Ecosystem:** Go
**Package:** `goshs.de/goshs/v2` (`github.com/patrickhener/goshs`)
**Affected:** `<=...
**Ecosystem:** Go
**Package:** `goshs.de/goshs/v2` (`github.com/patrickhener/goshs`)
**Affected:** `<=...
๐จ CVE-2026-50139
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same `Downloaded`/`DownloadLimit` snapshot, all pass the check, and all are served โ exceeding the operator's intended cap. Version 2.1.0 patches the issue.
๐@cveNotify
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same `Downloaded`/`DownloadLimit` snapshot, all pass the check, and all are served โ exceeding the operator's intended cap. Version 2.1.0 patches the issue.
๐@cveNotify
GitHub
Share-link ?token=โฆ redemption races past download limit
# Share-link `?token=โฆ` redemption races past download limit
**Ecosystem:** Go
**Package:** `goshs.de/goshs/v2` (`github.com/patrickhener/goshs`)
**Affected:** `<= v2.0.9` (every release th...
**Ecosystem:** Go
**Package:** `goshs.de/goshs/v2` (`github.com/patrickhener/goshs`)
**Affected:** `<= v2.0.9` (every release th...
๐จ CVE-2026-50187
Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory change into a folder containing a .env file, allowing syntactically valid shell commands in the file to execute with the current account's privileges, including without a prompt when ZSH_DOTENV_PROMPT=false or after the default prompt accepts an empty Enter response. This issue is fixed in versions released after 2026-05-28.
๐@cveNotify
Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory change into a folder containing a .env file, allowing syntactically valid shell commands in the file to execute with the current account's privileges, including without a prompt when ZSH_DOTENV_PROMPT=false or after the default prompt accepts an empty Enter response. This issue is fixed in versions released after 2026-05-28.
๐@cveNotify
GitHub
fix(dotenv): introduce safe parsing of .env files (#13778) ยท ohmyzsh/ohmyzsh@d170d18
* fix(dotenv): expect explicit yes before loading .env file
* fix(dotenv): implement secure parsing for .env files and add comprehensive tests
* feat(dotenv): check for .env file size to prevent Do...
* fix(dotenv): implement secure parsing for .env files and add comprehensive tests
* feat(dotenv): check for .env file size to prevent Do...
๐จ CVE-2026-56684
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node and producing a use-after-free that can crash the server or potentially allow remote code execution when TLS is enabled. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.
๐@cveNotify
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node and producing a use-after-free that can crash the server or potentially allow remote code execution when TLS is enabled. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.
๐@cveNotify
GitHub
Fix use-after-free in tlsProcessPendingData() on CLIENT KILL (#4234) ยท valkey-io/valkey@7cd5bcb
`tlsProcessPendingData()` walked `pending_list` with a `listIter`, which
caches the next node. A handler invoked during the walk (e.g. `CLIENT
KILL` -> `freeClient` -> `connTLSClose` ...
caches the next node. A handler invoked during the walk (e.g. `CLIENT
KILL` -> `freeClient` -> `connTLSClose` ...
๐จ CVE-2026-59825
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and TLS certificate verification globally for requests made by puma web processes while sidekiq background jobs remain unaffected. This issue is fixed in versions 4.4.19 and 4.5.12.
๐@cveNotify
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and TLS certificate verification globally for requests made by puma web processes while sidekiq background jobs remain unaffected. This issue is fixed in versions 4.4.19 and 4.5.12.
๐@cveNotify
GitHub
LDAP: Fix attempted modification of frozen hash (#39571) ยท mastodon/mastodon@2ccb6ef
Your self-hosted, globally interconnected microblogging community - LDAP: Fix attempted modification of frozen hash (#39571) ยท mastodon/mastodon@2ccb6ef
๐จ CVE-2026-59940
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potentially unintended server-side invocation or remote code execution when downstream frameworks register callable wrappers. This issue is fixed in version 1.5.3.
๐@cveNotify
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potentially unintended server-side invocation or remote code execution when downstream frameworks register callable wrappers. This issue is fixed in version 1.5.3.
๐@cveNotify
GitHub
`seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
## Summary
A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input to cause Promise control nodes to operate on values from the general deserialization reference ta...
A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input to cause Promise control nodes to operate on values from the general deserialization reference ta...