Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.9 CVE-2026-12089

WS Optimize – All-in-One Speed Booster & Cache Tools <= 3.3.19 - Authenticated (Editor+) Arbitrary File Read_CVE-2026-12089

The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and includin...

aurelienlws LWS Optimize – All-in-One Speed Booster & Cache Tools CVE
NONE FE5E2AC9-8661-

kiro-cybersecurity-skills_FE5E2AC9-8661-50CF-9897-C92032574F1D

CyberSecurity Skills A collection of 15 security workflows covering the full offensive-to-defensive spectrum. Each domain has a dedicated steering ...

N/A N/A GITHUBEXPLOIT
HIGH 8.7 CVE-2026-53868

Capgo < 12.128.2 - Denial of Service via Unverified Email Account Registration and Deletion_CVE-2026-53868

Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary email addresses without ve...

Capgo Capgo CVE
MEDIUM 5.3 CVE-2026-53867

Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement_CVE-2026-53867

Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can acce...

Cap-go capgo CVE
MEDIUM 6 CVE-2026-53839

OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint Validation_CVE-2026-53839

OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching hostname prefixes instead of ex...

OpenClaw OpenClaw CVE
MEDIUM 6 CVE-2026-53838

OpenClaw < 2026.5.27 - Node Pairing State Mutation via Reconnection_CVE-2026-53838

OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope d...

OpenClaw OpenClaw CVE
MEDIUM 6.3 CVE-2026-53837

OpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event Handlers_CVE-2026-53837

OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel type metadat...

OpenClaw OpenClaw CVE
HIGH 8.7 CVE-2026-53836

OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases_CVE-2026-53836

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows attackers to execute encode...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-53835

OpenClaw < 2026.5.6 - Config-Write Enforcement Bypass in Feishu Dynamic-Agent Bindings_CVE-2026-53835

OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that allows authenticated sende...

OpenClaw OpenClaw CVE
HIGH 8.2 CVE-2026-53834

OpenClaw < 2026.4.27 - Authorization Bypass in QQBot Pre-dispatch Slash Commands_CVE-2026-53834

OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allows authenticated senders to ...

OpenClaw OpenClaw CVE