๐จ CVE-2026-69189
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data, while toggleHistoryStarStatus and removeRequestFromHistory in the UserHistory service accept another user's history identifier without enforcing userUid ownership, allowing an authenticated workspace member to read private request history, session data, request contents, authorization headers, environment values, and settings and to modify or delete the victim's private history entries. This issue is fixed in version 2026.6.0.
๐@cveNotify
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data, while toggleHistoryStarStatus and removeRequestFromHistory in the UserHistory service accept another user's history identifier without enforcing userUid ownership, allowing an authenticated workspace member to read private request history, session data, request contents, authorization headers, environment values, and settings and to modify or delete the victim's private history entries. This issue is fixed in version 2026.6.0.
๐@cveNotify
GitHub
fix(backend): enforce ownership on user history and private User fielโฆ ยท hoppscotch/hoppscotch@9cc980b
โฆds (#6409)
* fix(backend): enforce ownership on user history and private User fields
* test: fix unit test cases
* fix(backend): gate private User field resolvers to their owner
* fix(backend)...
* fix(backend): enforce ownership on user history and private User fields
* test: fix unit test cases
* fix(backend): gate private User field resolvers to their owner
* fix(backend)...
๐จ CVE-2026-70657
Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the containing folder even though both features are disabled by default and must be explicitly enabled in the volume flags. This issue is fixed in version 1.20.17.
๐@cveNotify
Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the containing folder even though both features are disabled by default and must be explicitly enabled in the volume flags. This issue is fixed in version 1.20.17.
๐@cveNotify
GitHub
fix GHSA-x5pq-m9p8-f4vx; no dk with fk ยท 9001/copyparty@e407553
Portable file server with accelerated resumable uploads, dedup, WebDAV, SFTP, FTP, TFTP, zeroconf, media indexer, thumbnails++ all in one file - fix GHSA-x5pq-m9p8-f4vx; no dk with fk ยท 9001/copyparty@e407553
๐จ CVE-2026-71539
n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation allows an authenticated workflow user to swap a validated directory for a symlink before cloning, planting a crafted repository in the community node directory that loads as a custom JavaScript node after restart and executes arbitrary code on the server. This issue is fixed in versions 1.123.64, 2.29.8, and 2.30.1.
๐@cveNotify
n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation allows an authenticated workflow user to swap a validated directory for a symlink before cloning, planting a crafted repository in the community node directory that loads as a custom JavaScript node after restart and executes arbitrary code on the server. This issue is fixed in versions 1.123.64, 2.29.8, and 2.30.1.
๐@cveNotify
GitHub
Release n8n@1.123.64 ยท n8n-io/n8n
1.123.64 (2026-07-08)
๐จ CVE-2026-73181
Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.
๐@cveNotify
Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.
๐@cveNotify
๐จ CVE-2026-73187
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
๐@cveNotify
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress Sticky Chat Widget Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73189
Subscriber Insecure Direct Object References (IDOR) in WP Crowdfunding < 2.2.1 versions.
๐@cveNotify
Subscriber Insecure Direct Object References (IDOR) in WP Crowdfunding < 2.2.1 versions.
๐@cveNotify
๐จ CVE-2026-73190
Unauthenticated Cross Site Scripting (XSS) in WPDM โ Premium Packages <= 7.0.5 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WPDM โ Premium Packages <= 7.0.5 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WPDM โ Premium Packages Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73338
Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.
๐@cveNotify
๐จ CVE-2026-73339
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
๐@cveNotify
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress Modern Events Calendar Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73341
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
๐@cveNotify
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
๐@cveNotify
Patchstack
PHP Object Injection in WordPress RegistrationMagic Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73342
Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WP Multilang Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73343
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
๐@cveNotify
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
๐@cveNotify
๐จ CVE-2026-73345
Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
๐@cveNotify
Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress License Manager for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73350
Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.
๐@cveNotify
Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.
๐@cveNotify
Patchstack
Broken Authentication in WordPress SupportCandy Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73351
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WordPress Social Login and Register Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73352
Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.
๐@cveNotify
Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.
๐@cveNotify
๐จ CVE-2026-73355
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
๐@cveNotify
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress Affiliates Manager Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73358
Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Affiliates Manager Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73359
Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.
๐@cveNotify
Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-73360
Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Chaty Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.