🚨 CVE-2026-87793
The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file,
allowing an unauthenticated attacker to execute arbitrary JavaScript in
a victim's browser via a crafted URL containing a malicious archive parameter.
🎖@cveNotify
The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file,
allowing an unauthenticated attacker to execute arbitrary JavaScript in
a victim's browser via a crafted URL containing a malicious archive parameter.
🎖@cveNotify
GitHub
GitHub - italia/design-scuole-wordpress-theme: Tema Wordpress dedicato al progetto per i siti delle scuole
Tema Wordpress dedicato al progetto per i siti delle scuole - italia/design-scuole-wordpress-theme
🚨 CVE-2026-88620
SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or data-scope authorization, allowing an authenticated low-privileged employee to retrieve employee records belonging to other departments and users
🎖@cveNotify
SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or data-scope authorization, allowing an authenticated low-privileged employee to retrieve employee records belonging to other departments and users
🎖@cveNotify
GitHub
GitHub - 1024-lab/smart-admin: SmartAdmin国内首个以「高质量代码」为核心,「简洁、高效、安全」快速开发平台;基于SpringBoot2/3 + Sa-Token + Mybatis-Plus 和 Vue3 + Vite5…
SmartAdmin国内首个以「高质量代码」为核心,「简洁、高效、安全」快速开发平台;基于SpringBoot2/3 + Sa-Token + Mybatis-Plus 和 Vue3 + Vite5 + Ant Design Vue 4.x (同时支持JavaScript和TypeScript双版本);满足国家三级等保要求、支持登录限制、接口数据国产加解密、高防SQL注入等一系列安全体系。 ...
🚨 CVE-2026-88621
OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability in the Api::upload() method in class/Api.php. An authenticated administrator can submit a non-HTML upload filename matching an existing file in the application's working directory. The application passes the user-controlled filename to unlink() when rejecting the upload, potentially causing file deletion and denial of service.
🎖@cveNotify
OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability in the Api::upload() method in class/Api.php. An authenticated administrator can submit a non-HTML upload filename matching an existing file in the application's working directory. The application passes the user-controlled filename to unlink() when rejecting the upload, potentially causing file deletion and denial of service.
🎖@cveNotify
GitHub
GitHub - helloxz/onenav: 使用PHP + SQLite 3开发的书签管理系统,将浏览器书签集中式管理,做到一处部署,随处访问。
使用PHP + SQLite 3开发的书签管理系统,将浏览器书签集中式管理,做到一处部署,随处访问。 - helloxz/onenav
🚨 CVE-2026-89307
The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).
🎖@cveNotify
The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).
🎖@cveNotify
GitHub
GitHub - italia/design-scuole-wordpress-theme: Tema Wordpress dedicato al progetto per i siti delle scuole
Tema Wordpress dedicato al progetto per i siti delle scuole - italia/design-scuole-wordpress-theme
🚨 CVE-2026-91848
A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the file /index.php?m=content&f=article&v=getDataOfJson. The manipulation of the argument title/master_table leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
🎖@cveNotify
A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the file /index.php?m=content&f=article&v=getDataOfJson. The manipulation of the argument title/master_table leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
🎖@cveNotify
GitHub
GitHub - wuzhicms/wuzhicms: php 内容管理系统
php 内容管理系统. Contribute to wuzhicms/wuzhicms development by creating an account on GitHub.
🚨 CVE-2026-91849
A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
🎖@cveNotify
A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
🎖@cveNotify
GitHub
GitHub - wuzhicms/wuzhicms: php 内容管理系统
php 内容管理系统. Contribute to wuzhicms/wuzhicms development by creating an account on GitHub.
🚨 CVE-2026-91929
Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets.
🎖@cveNotify
Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets.
🎖@cveNotify
GitHub
Cross-tenant/cross-org authorization gaps in Enterprise role, and SSO-config endpoints
### Summary
Five Enterprise-tier endpoints fetch or mutate a workspace/organization/role by a client-supplied id with no verification that it belongs to the acting user's own org/workspace. Al...
Five Enterprise-tier endpoints fetch or mutate a workspace/organization/role by a client-supplied id with no verification that it belongs to the acting user's own org/workspace. Al...
🚨 CVE-2026-91930
Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by exploiting insufficient tenant isolation in the organizationuser and workspace endpoints.
🎖@cveNotify
Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by exploiting insufficient tenant isolation in the organizationuser and workspace endpoints.
🎖@cveNotify
GitHub
Cross-tenant organization admin takeover via unscoped organization/workspace membership APIs
# Cross-tenant organization admin takeover via unscoped organization/workspace membership APIs
I am privately reporting a novel cross-tenant authorization bypass in Flowise Enterprise/Cloud mult...
I am privately reporting a novel cross-tenant authorization bypass in Flowise Enterprise/Cloud mult...
🚨 CVE-2026-91931
Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm packages to execute code on the Flowise server.
🎖@cveNotify
Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm packages to execute code on the Flowise server.
🎖@cveNotify
GitHub
Flowise Custom MCP npx package execution leads to authenticated server-side command execution
# Flowise Authenticated Command Execution via Custom MCP `npx`
## Summary
Flowise is an open-source visual platform for building LLM applications, chatflows, agents, and tool integrations. Fl...
## Summary
Flowise is an open-source visual platform for building LLM applications, chatflows, agents, and tool integrations. Fl...
🚨 CVE-2026-91932
Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working directory to execute malicious code.
🎖@cveNotify
Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working directory to execute malicious code.
🎖@cveNotify
GitHub
Flowise MCP Server Config cwd Parameter Validation Bypass
### Summary
A validation bypass in Flowise's MCP server configuration allows authenticated attackers to achieve arbitrary code execution by exploiting an unvalidated `cwd` parameter that bypas...
A validation bypass in Flowise's MCP server configuration allows authenticated attackers to achieve arbitrary code execution by exploiting an unvalidated `cwd` parameter that bypas...
🚨 CVE-2026-91933
Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve tool definitions and execute tools from victim workspaces, triggering external side effects and accessing sensitive tool outputs.
🎖@cveNotify
Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve tool definitions and execute tools from victim workspaces, triggering external side effects and accessing sensitive tool outputs.
🎖@cveNotify
GitHub
openai-realtime endpoints allow cross-workspace tool disclosure and execution via unscoped chatflow ID
### Summary
`GET /api/v1/openai-realtime/:id` and `POST /api/v1/openai-realtime/:id` in Flowise allow a user or API key from one workspace to disclose and execute tools belonging to a `ChatFlow`...
`GET /api/v1/openai-realtime/:id` and `POST /api/v1/openai-realtime/:id` in Flowise allow a user or API key from one workspace to disclose and execute tools belonging to a `ChatFlow`...
🚨 CVE-2026-91934
Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to system directories or inject files into the web root to execute commands or perform stored XSS attacks.
🎖@cveNotify
Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to system directories or inject files into the web root to execute commands or perform stored XSS attacks.
🎖@cveNotify
GitHub
Flowise RCE via SQL Database Chain Node
=============================================================================
Security Advisory
...
Security Advisory
...
🚨 CVE-2026-91935
Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys by redirecting requests to cloud metadata services or internal hosts.
🎖@cveNotify
Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys by redirecting requests to cloud metadata services or internal hosts.
🎖@cveNotify
GitHub
SSRF + LLM API key exfiltration via user-controlled basepath / baseUrl in 8 chat-model nodes
### Summary
Flowise chat-model nodes accept an attacker-controlled `basepath` / `baseUrl` input and pass it **directly** into the underlying LangChain SDK as the LLM provider's `baseURL`, by...
Flowise chat-model nodes accept an attacker-controlled `basepath` / `baseUrl` input and pass it **directly** into the underlying LangChain SDK as the LLM provider's `baseURL`, by...
🚨 CVE-2026-91936
Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens.
🎖@cveNotify
Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute arbitrary commands and steal AWS credentials and Docker Hub tokens.
🎖@cveNotify
GitHub
Script injection in Docker image build workflows allows secret theft
### Summary
8 script injection vulnerabilities across 3 Docker image build workflows allow a user with write access to steal AWS credentials and Docker Hub tokens by injecting shell commands thr...
8 script injection vulnerabilities across 3 Docker image build workflows allow a user with write access to steal AWS credentials and Docker Hub tokens by injecting shell commands thr...
🚨 CVE-2026-91937
Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection.
🎖@cveNotify
Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection.
🎖@cveNotify
GitHub
Cross-Session Data Leakage via NoSQL Injection in MongoDBMemory Node
### Summary
The `MongoDBMemory` node (MongoDB Atlas Chat Memory) in Flowise fails to sanitize the `overrideConfig.sessionId` parameter before using it as a MongoDB query value. An unauthenticate...
The `MongoDBMemory` node (MongoDB Atlas Chat Memory) in Flowise fails to sanitize the `overrideConfig.sessionId` parameter before using it as a MongoDB query value. An unauthenticate...
🚨 CVE-2026-91938
Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as document text.
🎖@cveNotify
Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as document text.
🎖@cveNotify
GitHub
SSRF bypass via Cheerio/Playwright/Puppeteer document loaders — not covered by httpSecurity deny list
## Summary
The Cheerio, Playwright, and Puppeteer document loader nodes fetch user-provided URLs without calling `checkDenyList()` or using `secureFetch`. They instantiate LangChain's built-...
The Cheerio, Playwright, and Puppeteer document loader nodes fetch user-provided URLs without calling `checkDenyList()` or using `secureFetch`. They instantiate LangChain's built-...
🚨 CVE-2026-91940
crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any directory accessible to the service account.
🎖@cveNotify
crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any directory accessible to the service account.
🎖@cveNotify
GitHub
Arbitrary file write via unconfined PDFContentScrapingStrategy fields in untrusted config bodies
The Docker API loads request-body configs with Provenance.UNTRUSTED. _filter_untrusted_fields (crawl4ai/async_configs.py) is meant to drop unsafe fields, but it fails open: when a type has no entry...
🚨 CVE-2026-91941
Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and bandwidth on shared workers.
🎖@cveNotify
Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and bandwidth on shared workers.
🎖@cveNotify
GitHub
Denial of Service in PDFContentScrapingStrategy: unbounded remote PDF size and page count
### Summary
When an untrusted client selects `PDFContentScrapingStrategy` on the Docker
API, the server downloads and parses a remote PDF with no limit on file size,
page count, or (by default) ...
When an untrusted client selects `PDFContentScrapingStrategy` on the Docker
API, the server downloads and parses a remote PDF with no limit on file size,
page count, or (by default) ...
🚨 CVE-2026-91942
crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute JavaScript in the Playground origin and steal API tokens from sessionStorage for authenticated API abuse.
🎖@cveNotify
crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute JavaScript in the Playground origin and steal API tokens from sessionStorage for authenticated API abuse.
🎖@cveNotify
GitHub
XSS in Docker Playground: crawl results rendered via innerHTML; PDF pipeline emits unescaped HTML
### Summary
The Docker Playground UI displays crawl results by assigning untrusted text to
`element.innerHTML`, which re-parses it as HTML. Combined with the PDF text
pipeline emitting unescaped...
The Docker Playground UI displays crawl results by assigning untrusted text to
`element.innerHTML`, which re-parses it as HTML. Combined with the PDF text
pipeline emitting unescaped...
🚨 CVE-2026-91943
Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation. Authenticated attackers can supply URLs that redirect to internal addresses or use DNS rebinding to access internal services, exfiltrating responses through PDF text extraction in crawl results.
🎖@cveNotify
Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation. Authenticated attackers can supply URLs that redirect to internal addresses or use DNS rebinding to access internal services, exfiltrating responses through PDF text extraction in crawl results.
🎖@cveNotify
GitHub
SSRF in PDFContentScrapingStrategy: PDF download follows redirects and bypasses egress SSRF controls
### Summary
The Docker API server validates the destination of a crawl's *seed* URL, but
`PDFContentScrapingStrategy` re-downloads the target with Python `requests`
(`allow_redirects=True`) ...
The Docker API server validates the destination of a crawl's *seed* URL, but
`PDFContentScrapingStrategy` re-downloads the target with Python `requests`
(`allow_redirects=True`) ...
🚨 CVE-2026-91944
crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON responses as HTML. Attackers can inject malicious scripts through crawled page content like the page title to steal the operator's API token from sessionStorage and gain full server control.
🎖@cveNotify
crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON responses as HTML. Attackers can inject malicious scripts through crawled page content like the page title to steal the operator's API token from sessionStorage and gain full server control.
🎖@cveNotify
GitHub
DOM-based XSS in Docker Playground UI leads to operator API-token theft
# [SECURITY] DOM-based XSS in the Docker Playground UI → operator API-token theft → full server takeover
**Component:** `deploy/docker` — Playground UI (`deploy/docker/static/playground/index.ht...
**Component:** `deploy/docker` — Playground UI (`deploy/docker/static/playground/index.ht...