CVE Notify
19.7K subscribers
4 photos
303K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-79483
FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in unauthorized access to chat history titles of all users across the platform.

πŸŽ–@cveNotify
🚨 CVE-2026-81278
Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects Post SMTP: from 4.0.0 through beta.1.

πŸŽ–@cveNotify
🚨 CVE-2026-81280
Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.

πŸŽ–@cveNotify
🚨 CVE-2026-81287
Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.

πŸŽ–@cveNotify
🚨 CVE-2026-81291
Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions.

πŸŽ–@cveNotify
🚨 CVE-2026-81293
Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.

πŸŽ–@cveNotify
🚨 CVE-2026-81779
Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted.

This issue affects Newspapers X: from 1.0.46 through 1.0.48.

πŸŽ–@cveNotify
🚨 CVE-2026-81887
Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the __proto__, constructor, and prototype path segments and creates inherited objects. Client-side state handlers then access effects.html, effects.js, effects.xjs, and effects.scripts without Object.prototype.hasOwnProperty.call(), allowing inherited attacker-controlled state to be treated as trusted effects. An unauthenticated attacker can craft a URL that, when opened by a user, executes arbitrary JavaScript in the affected application's origin. Exploitation requires user interaction and does not bypass server-side authorization or grant privileges beyond the affected user. This issue is fixed in versions 3.8.3 and 4.3.4.

πŸŽ–@cveNotify
🚨 CVE-2026-81888
@hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine login attempt. This defeats the `state`-based CSRF protection under default usage. Version 0.8.6 has a patch.

πŸŽ–@cveNotify