Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-56235

Capgo – Unauthenticated Cross-Tenant Metrics Disclosure via RPC Functions_CVE-2026-56235

Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metrics, get_global_metrics, get...

Cap-go capgo CVE
MEDIUM 6.9 CVE-2026-56228

Capgo – Denial of Service via Improper Password Policy Length Validation_CVE-2026-56228

Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated ...

Capgo Capgo CVE
MEDIUM 5.3 CVE-2026-56227

Capgo – Server-Side Request Forgery via Webhook URL Validation_CVE-2026-56227

Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. O...

Capgo Capgo CVE
MEDIUM 6.9 CVE-2026-56218

Capgo – EXIF Metadata Exposure via Image Upload_CVE-2026-56218

Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing information disclosure. Attackers ...

Capgo Capgo CVE
MEDIUM 5.1 CVE-2025-71331

Flowise – Cross-Site Scripting in Chat Messages and Agent Workflows_CVE-2025-71331

Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent f...

Flowise Flowise CVE
MEDIUM 5.9 CVE-2026-12673

CVE-2026-12673_CVE-2026-12673

Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a secon...

liquidfiles liquidfiles CVE
MEDIUM 6.5 CVE-2026-12119

Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute_CVE-2026-12119

The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the 'frontmanage' s...

eemitch Simple File List CVE
MEDIUM 6.9 CVE-2026-56213

Capgo – Unauthenticated Cross-Tenant Metrics Poisoning via upsert_version_meta RPC_CVE-2026-56213

Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER function exposed via PostgR...

Capgo Capgo CVE
MEDIUM 5.1 CVE-2026-56212

Capgo – Improper 2FA Enforcement Logic via Team Security Settings_CVE-2026-56212

Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable man...

Capgo Capgo CVE
MEDIUM 6.9 CVE-2026-56080

Cap-go – Authentication Logic Flaw in Enforce Password Policy_CVE-2026-56080

Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and successfully changes their...

Cap-go capgo CVE