Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-56347

AVideo TopMenu Plugin – Stored Cross-Site Scripting via Unescaped Menu Item Fields_CVE-2026-56347

AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering due to missing output encodi...

WWBN AVideo CVE
MEDIUM 6.9 CVE-2026-56346

AVideo – Unauthenticated PGP Message Decryption via decryptMessage.json.php Endpoint_CVE-2026-56346

AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that allows unauthenticated use...

AVideo AVideo CVE
MEDIUM 6.1 CVE-2026-56342

AVideo – Server-Side Request Forgery in Live/test.php via statsURL Parameter_CVE-2026-56342

AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows authenticated administrators t...

AVideo AVideo CVE
MEDIUM 5.3 CVE-2025-71379

vllm – Regular Expression Denial of Service in Multiple Components_CVE-2025-71379

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/...

vllm vllm 0.6.3 CVE
MEDIUM 5.1 CVE-2026-56332

Capgo – Open Redirect via confirmation_url Parameter_CVE-2026-56332

Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to redirect users to arbitrary e...

Capgo Capgo CVE
MEDIUM 4.8 CVE-2026-56330

Capgo – Open Redirect via Unvalidated Stripe Billing URLs_CVE-2026-56330

Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept unvalidated callbackUrl, s...

Capgo Capgo CVE
MEDIUM 5.3 CVE-2026-56319

Capgo – App Existence Oracle via GET /statistics/app/:app_id_CVE-2026-56319

Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endpoint that allows app-limited API keys...

Capgo Capgo CVE
MEDIUM 5.3 CVE-2026-56307

Cap-go – Broken Cursor Pagination in /private/devices Endpoint_CVE-2026-56307

Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudflare/workerd path that allo...

Cap-go capgo CVE
MEDIUM 6.9 CVE-2026-56304

picklescan – Arbitrary File Creation via logging.FileHandler Deserialization_CVE-2026-56304

picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte fi...

picklescan picklescan CVE
MEDIUM 5.3 CVE-2026-56295

Capgo – Policy Enforcement Bypass in Webhook Management Endpoints via Non-Expiring API Keys_CVE-2026-56295

Capgo before 12.128.2 contains an authorization bypass vulnerability in webhook management endpoints that allows non-expiring API keys to bypass th...

Capgo Capgo CVE