Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.3 CVE-2026-9029

Stored XSS via Geomap Panel Template Variable Attribution Injection_CVE-2026-9029

The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug. sanitizeTextPanelContent() runs on the raw template string before g...

Grafana Grafana OSS 12.4.0 CVE
LOW 3.8 CVE-2026-8074

Improper Permission Check Allows User Manager to Deactivate Bot Accounts_CVE-2026-8074

Mattermost versions 11.7.x

Mattermost Mattermost 11.7.0 CVE
MEDIUM 6.9 CVE-2026-7167

Multiple vulnerabilities in the Assassin game by Gaudire_CVE-2026-7167

The vulnerability arises when the system fails to properly validate the 'email' field during the authentication process, allowing unverified or fak...

Gaudire Assassin game last version CVE
CRITICAL 9.2 CVE-2026-7166

Multiple vulnerabilities in the Assassin game by Gaudire_CVE-2026-7166

Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and phone number data from the ‘...

Gaudire Assassin game last version CVE
CRITICAL 9.4 CVE-2026-7165

Multiple vulnerabilities in the Assassin game by Gaudire_CVE-2026-7165

The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters allow the modification of ot...

Gaudire Assassin game last version CVE
MEDIUM 6.4 CVE-2026-6673

Mattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud install_CVE-2026-6673

Mattermost versions 11.7.x

Mattermost Mattermost 11.7.0 CVE
HIGH 7 CVE-2026-6653

libxml2: Use after free in xmlParseInternalSubset via improper entity resolution handling_CVE-2026-6653

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-servic...

GNOME libxml2 2.9.11 CVE
MEDIUM 6.4 CVE-2026-6062

IDOR in Jira plugin subscription edit endpoint_CVE-2026-6062

Mattermost versions 11.7.x

Mattermost Mattermost 11.7.0 CVE
MEDIUM 5.4 CVE-2026-5139

GitLab Plugin Allows Non-Admin Users to Modify Default Instance Configuration_CVE-2026-5139

Mattermost versions 11.7.x

Mattermost Mattermost 11.7.0 CVE
MEDIUM 5.1 CVE-2026-56450

AIL Framework – Missing Rate Limiting Enables Brute-Force Attacks Against Two-Factor Authentication Codes_CVE-2026-56450

AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached the 2FA verification st...

ail project ail framework CVE