Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.1 CVE-2026-9843

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value_CVE-2026-9843

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pa...

crmperks Database for Contact Form 7, WPforms, Elementor forms CVE
HIGH 8.7 CVE-2026-56082

Supabase – Unauthenticated Cross-Tenant Billing Log Tampering via public.record_build_time RPC_CVE-2026-56082

Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record...

Cap-go capgo CVE
CRITICAL 9.3 CVE-2026-56081

Cap-go – Account Lockout via 2FA Misconfiguration on Unverified Email_CVE-2026-56081

Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email addres...

Cap-go capgo CVE
MEDIUM 6.9 CVE-2026-56080

Cap-go – Authentication Logic Flaw in Enforce Password Policy_CVE-2026-56080

Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and successfully changes their...

Cap-go capgo CVE
HIGH 7.1 CVE-2026-56079

Capgo – Cross-Tenant Authorization Bypass via PostgREST Webhook Access_CVE-2026-56079

Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-scoped read API keys to acc...

Capgo Capgo CVE
CRITICAL 9.3 CVE-2026-56073

Cap-go – OTP Bypass via Response Manipulation in Email Verification_CVE-2026-56073

Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by mo...

Cap-go capgo CVE
CRITICAL 9.8 CVE-2026-11551

Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover_CVE-2026-11551

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is du...

wpmudev Branda – White Label & Branding, Free Login Page Customizer CVE
MEDIUM 5.3 CVE-2026-49345

Mercator CVE Configuration Vulnerable to Server-Side Request Forgery (SSRF)_CVE-2026-49345

Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, a Server-Side Request Forge...

sourcentis mercator < 2025.05.19 CVE
HIGH 7.1 CVE-2026-49344

Mercator has a Personal Identifiable Information Leak from Query Executor feature_CVE-2026-49344

Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, Mercator's Query Engine (`/...

sourcentis mercator < 2025.05.19 CVE
MEDIUM 5.3 CVE-2026-49342

YARD static cache reads raw traversal paths before router sanitization_CVE-2026-49342

YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path...

lsegal yard < 0.9.44 CVE