CVE Notify
19.7K subscribers
4 photos
303K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2026-79408
An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-79483
FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all users across the platform.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-81278
Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects Post SMTP: from 4.0.0 through beta.1.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-81280
Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-81287
Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-81291
Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-81293
Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-81779
Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted.

This issue affects Newspapers X: from 1.0.46 through 1.0.48.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-81887
Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the __proto__, constructor, and prototype path segments and creates inherited objects. Client-side state handlers then access effects.html, effects.js, effects.xjs, and effects.scripts without Object.prototype.hasOwnProperty.call(), allowing inherited attacker-controlled state to be treated as trusted effects. An unauthenticated attacker can craft a URL that, when opened by a user, executes arbitrary JavaScript in the affected application's origin. Exploitation requires user interaction and does not bypass server-side authorization or grant privileges beyond the affected user. This issue is fixed in versions 3.8.3 and 4.3.4.

๐ŸŽ–@cveNotify