π¨ CVE-2026-78281
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress CP Media Player Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78283
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Music Player for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78286
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
π@cveNotify
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
π@cveNotify
Patchstack
PHP Object Injection in WordPress Geo Controller Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78288
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
π@cveNotify
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
π@cveNotify
Patchstack
SQL Injection in WordPress Beautiful Taxonomy Filters Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78289
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress CozyStay Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78292
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
π@cveNotify
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
π@cveNotify
Patchstack
PHP Object Injection in WordPress Hash Form Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-78293
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
π@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
π@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WP w3all phpBB Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-80433
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
π@cveNotify
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
π@cveNotify
Patchstack
Sensitive Data Exposure in WordPress SureFeedback Client Site Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-81271
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
π@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
π@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress GeoDirectory Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-81272
Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.
π@cveNotify
Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress FluentPlayer Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-81273
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
π@cveNotify
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
π@cveNotify
Patchstack
Cross Site Request Forgery (CSRF) in WordPress FluentBooking Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-81276
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
π@cveNotify
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
π@cveNotify
Patchstack
Broken Access Control in WordPress Kali Forms Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-81277
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
π@cveNotify
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
π@cveNotify
Patchstack
SQL Injection in WordPress Suggestion Engine for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-81279
Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.
π@cveNotify
Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.
π@cveNotify
π¨ CVE-2026-81560
A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of the file src/web/server.ts of the component Static File Handler. Such manipulation of the argument req.url leads to path traversal. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of the file src/web/server.ts of the component Static File Handler. Such manipulation of the argument req.url leads to path traversal. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - blackms/aistack: Production-grade agent orchestration for Claude Code - 11 agents, 46 MCP tools, SQLite+FTS5, drift detectionβ¦
Production-grade agent orchestration for Claude Code - 11 agents, 46 MCP tools, SQLite+FTS5, drift detection, consensus checkpoints - blackms/aistack
π¨ CVE-2026-81562
A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the file src/adb/client.ts. Performing a manipulation results in os command injection. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.10.3 is able to mitigate this issue. The patch is named a86d9e55694c98a122943eeff859461d0b9aa6d6. It is suggested to upgrade the affected component.
π@cveNotify
A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the file src/adb/client.ts. Performing a manipulation results in os command injection. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.10.3 is able to mitigate this issue. The patch is named a86d9e55694c98a122943eeff859461d0b9aa6d6. It is suggested to upgrade the affected component.
π@cveNotify
GitHub
GitHub - AlexGladkov/claude-in-mobile: MCP server for mobile and desktop automation β Android (via ADB), iOS Simulator (via simctl)β¦
MCP server for mobile and desktop automation β Android (via ADB), iOS Simulator (via simctl), and Desktop (Compose Multiplatform). Like Claude in Chrome but for mobile devices and desktop apps - Al...
π¨ CVE-2026-81833
A security flaw has been discovered in RooCodeInc Roo-Code up to 3.51.1. Affected by this vulnerability is the function optimizeQuery of the file src/utils/helpers.ts of the component CodeIndexManager. Performing a manipulation results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.
π@cveNotify
A security flaw has been discovered in RooCodeInc Roo-Code up to 3.51.1. Affected by this vulnerability is the function optimizeQuery of the file src/utils/helpers.ts of the component CodeIndexManager. Performing a manipulation results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.
π@cveNotify
Gist
Roo-Code v3.51.1 - RAG Comment Injection Advisory
Roo-Code v3.51.1 - RAG Comment Injection Advisory. GitHub Gist: instantly share code, notes, and snippets.
π¨ CVE-2026-81834
A weakness has been identified in RooCodeInc Roo-Code up to 3.51.1. Affected by this issue is the function ExecaTerminalProcess of the component README File Handler. Executing a manipulation can lead to code injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.
π@cveNotify
A weakness has been identified in RooCodeInc Roo-Code up to 3.51.1. Affected by this issue is the function ExecaTerminalProcess of the component README File Handler. Executing a manipulation can lead to code injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.
π@cveNotify
Gist
Roo-Code v3.51.1 - README Prompt Injection Advisory
Roo-Code v3.51.1 - README Prompt Injection Advisory - README.md
π¨ CVE-2026-81836
A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file src/integrations/claude-code/oauth.ts of the component OAuth Callback. The manipulation results in cleartext transmission of sensitive information. The attack may be performed from remote. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit is now public and may be used. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.
π@cveNotify
A vulnerability was detected in RooCodeInc Roo-Code up to 3.51.1. This vulnerability affects unknown code of the file src/integrations/claude-code/oauth.ts of the component OAuth Callback. The manipulation results in cleartext transmission of sensitive information. The attack may be performed from remote. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit is now public and may be used. Multiple isses were reported to the vendor beforehand. They explain, that "they all apply to Roo Code, a project we no longer support - the repository was archived a while ago, and we don't encourage anyone to use it." This vulnerability only affects products that are no longer supported by the maintainer.
π@cveNotify
Gist
Roo-Code v3.51.1 - OAuth Cleartext Advisory
Roo-Code v3.51.1 - OAuth Cleartext Advisory. GitHub Gist: instantly share code, notes, and snippets.