CVE Notify
19.6K subscribers
4 photos
310K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2026-69189
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data, while toggleHistoryStarStatus and removeRequestFromHistory in the UserHistory service accept another user's history identifier without enforcing userUid ownership, allowing an authenticated workspace member to read private request history, session data, request contents, authorization headers, environment values, and settings and to modify or delete the victim's private history entries. This issue is fixed in version 2026.6.0.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-70657
Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the containing folder even though both features are disabled by default and must be explicitly enabled in the volume flags. This issue is fixed in version 1.20.17.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-71539
n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation allows an authenticated workflow user to swap a validated directory for a symlink before cloning, planting a crafted repository in the community node directory that loads as a custom JavaScript node after restart and executes arbitrary code on the server. This issue is fixed in versions 1.123.64, 2.29.8, and 2.30.1.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-73181
Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-73189
Subscriber Insecure Direct Object References (IDOR) in WP Crowdfunding < 2.2.1 versions.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-73338
Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-73343
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-73352
Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.

๐ŸŽ–@cveNotify