Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-56235

Capgo – Unauthenticated Cross-Tenant Metrics Disclosure via RPC Functions_CVE-2026-56235

Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metrics, get_global_metrics, get...

Cap-go capgo CVE
MEDIUM 6.9 CVE-2026-56228

Capgo – Denial of Service via Improper Password Policy Length Validation_CVE-2026-56228

Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated ...

Capgo Capgo CVE
MEDIUM 5.3 CVE-2026-56227

Capgo – Server-Side Request Forgery via Webhook URL Validation_CVE-2026-56227

Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. O...

Capgo Capgo CVE
MEDIUM 6.9 CVE-2026-56218

Capgo – EXIF Metadata Exposure via Image Upload_CVE-2026-56218

Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing information disclosure. Attackers ...

Capgo Capgo CVE
MEDIUM 5.1 CVE-2025-71331

Flowise – Cross-Site Scripting in Chat Messages and Agent Workflows_CVE-2025-71331

Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent f...

Flowise Flowise CVE
CRITICAL 9.9 CVE-2026-5366

Git Argument Injection in prefecthq/prefect_CVE-2026-5366

Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage clas...

prefecthq prefecthq/prefect unspecified CVE
LOW 2.3 CVE-2026-56325

Capgo – App ID Confusion via ILIKE Wildcard in Preview Subdomain Lookup_CVE-2026-56325

Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain resolver, allowing underscor...

Capgo Capgo CVE
LOW 2.3 CVE-2026-56317

Nuxt – Cross-Site Scripting via NoScript Component Slot Content_CVE-2026-56317

Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot conte...

Nuxt Nuxt 4.0.0 CVE
CRITICAL 10 CVE-2026-48939

Joomla Extension – icagenda.com – Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15_CVE-2026-48939

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in P...

icagenda.com iCagenda extension for Joomla 1.0.0-3.9.14 CVE
CRITICAL 9.5 CVE-2026-48909

Joomla Extension – joomshaper.com – PHP Object injection in SP LMS extension for Joomla < 4.1.4_CVE-2026-48909

SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker t...

joomshaper.net SP LMS extension for Joomla 1.0.0-4.1.3 CVE