Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 10 CVE-2026-48908

Joomla Extension – joomshaper.com – Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.12_CVE-2026-48908

A vulnerability in the SP Page Builder for Joomla allows the upload of arbitrary files for unauthenticated users, ultimately resulting in PHP code ...

joomshaper.net SP Page Builder extension for Joomla 1.0.0-6.6.1 CVE
MEDIUM 5.9 CVE-2026-12673

CVE-2026-12673_CVE-2026-12673

Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a secon...

liquidfiles liquidfiles CVE
MEDIUM 6.5 CVE-2026-12119

Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute_CVE-2026-12119

The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the 'frontmanage' s...

eemitch Simple File List CVE
HIGH 7.5 CVE-2026-11912

Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action_CVE-2026-11912

The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up ...

eemitch Simple File List CVE
HIGH 7.5 CVE-2026-11911

Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter_CVE-2026-11911

The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile...

eemitch Simple File List CVE
HIGH 8.7 CVE-2026-56216

Capgo – Scope Escalation via API Key Creation in /functions/v1/apikey_CVE-2026-56216

Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows app-limited API keys to mint ...

Capgo Capgo CVE
HIGH 8.7 CVE-2026-56215

Capgo – Account Merge via Poisoned public.users.email in SSO Provisioning_CVE-2026-56215

Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, which the SSO provisioning end...

Capgo Capgo CVE
HIGH 8.7 CVE-2026-56214

Capgo – Unauthenticated Organization Enumeration and Billing Status Disclosure via Supabase RPC_CVE-2026-56214

Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_trial_org and is_paying_org that allo...

Capgo Capgo CVE
MEDIUM 6.9 CVE-2026-56213

Capgo – Unauthenticated Cross-Tenant Metrics Poisoning via upsert_version_meta RPC_CVE-2026-56213

Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER function exposed via PostgR...

Capgo Capgo CVE
MEDIUM 5.1 CVE-2026-56212

Capgo – Improper 2FA Enforcement Logic via Team Security Settings_CVE-2026-56212

Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable man...

Capgo Capgo CVE