Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2026-56216

Capgo – Scope Escalation via API Key Creation in /functions/v1/apikey_CVE-2026-56216

Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows app-limited API keys to mint ...

Capgo Capgo CVE
HIGH 8.7 CVE-2026-56215

Capgo – Account Merge via Poisoned public.users.email in SSO Provisioning_CVE-2026-56215

Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, which the SSO provisioning end...

Capgo Capgo CVE
HIGH 8.7 CVE-2026-56214

Capgo – Unauthenticated Organization Enumeration and Billing Status Disclosure via Supabase RPC_CVE-2026-56214

Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_trial_org and is_paying_org that allo...

Capgo Capgo CVE
MEDIUM 6.9 CVE-2026-56213

Capgo – Unauthenticated Cross-Tenant Metrics Poisoning via upsert_version_meta RPC_CVE-2026-56213

Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER function exposed via PostgR...

Capgo Capgo CVE
MEDIUM 5.1 CVE-2026-56212

Capgo – Improper 2FA Enforcement Logic via Team Security Settings_CVE-2026-56212

Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable man...

Capgo Capgo CVE
HIGH 8.1 CVE-2026-9843

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value_CVE-2026-9843

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pa...

crmperks Database for Contact Form 7, WPforms, Elementor forms CVE
HIGH 8.7 CVE-2026-56082

Supabase – Unauthenticated Cross-Tenant Billing Log Tampering via public.record_build_time RPC_CVE-2026-56082

Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record...

Cap-go capgo CVE
CRITICAL 9.3 CVE-2026-56081

Cap-go – Account Lockout via 2FA Misconfiguration on Unverified Email_CVE-2026-56081

Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email addres...

Cap-go capgo CVE
MEDIUM 6.9 CVE-2026-56080

Cap-go – Authentication Logic Flaw in Enforce Password Policy_CVE-2026-56080

Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and successfully changes their...

Cap-go capgo CVE
HIGH 7.1 CVE-2026-56079

Capgo – Cross-Tenant Authorization Bypass via PostgREST Webhook Access_CVE-2026-56079

Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-scoped read API keys to acc...

Capgo Capgo CVE