๐จ CVE-2026-81491
A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
๐@cveNotify
A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
๐@cveNotify
GitHub
Arbitrary File Read, Write, and Delete Vulnerability in with-context-mcp ยท Issue #2 ยท boxpositron/with-context-mcp
Arbitrary File Read, Write, and Delete Vulnerability in with-context-mcp 1) CNA / Submission Type Submission type: Report a vulnerability (CVE ID request) Reporter role: Independent security resear...
๐จ CVE-2026-27330
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Mobile App for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-32479
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
๐@cveNotify
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress Visitor Traffic Real Time Statistics Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-32564
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
๐@cveNotify
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-32566
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
๐@cveNotify
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
๐@cveNotify
Patchstack
Privilege Escalation in WordPress ACPT (Pro) - Custom Post Types Plugin for WordPress Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-78257
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
๐@cveNotify
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
๐@cveNotify
Patchstack
PHP Object Injection in WordPress Booking and Rental Manager Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-78261
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Realtyna Organic IDX plugin Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-78273
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
๐@cveNotify
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Fluent Boards Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-78274
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
๐@cveNotify
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
๐@cveNotify
Patchstack
Arbitrary File Upload in WordPress Fluent Boards Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-78275
Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.
๐@cveNotify
Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.
๐@cveNotify
Patchstack
Arbitrary File Deletion in WordPress Fluent Boards Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-78281
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress CP Media Player Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-78283
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Music Player for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-78286
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
๐@cveNotify
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
๐@cveNotify
Patchstack
PHP Object Injection in WordPress Geo Controller Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-78288
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
๐@cveNotify
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
๐@cveNotify
Patchstack
SQL Injection in WordPress Beautiful Taxonomy Filters Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-78289
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress CozyStay Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-78292
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
๐@cveNotify
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
๐@cveNotify
Patchstack
PHP Object Injection in WordPress Hash Form Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
๐จ CVE-2026-78293
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WP w3all phpBB Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.