Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-56325

Capgo – App ID Confusion via ILIKE Wildcard in Preview Subdomain Lookup_CVE-2026-56325

Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain resolver, allowing underscor...

Capgo Capgo CVE
LOW 2.3 CVE-2026-56317

Nuxt – Cross-Site Scripting via NoScript Component Slot Content_CVE-2026-56317

Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot conte...

Nuxt Nuxt 4.0.0 CVE
NONE HACKREAD:7261C7...

MDR Provider Comparison: Time to Discover and Respond to Threats_HACKREAD:7261C791BE2D3FF87A7C570142D9E829

A detailed MDR provider comparison covering tiers, response speed, coverage, threat intelligence, pricing, and breach warranties to help you choose.

N/A N/A HACKREAD
CRITICAL 10 CVE-2026-48939

Joomla Extension – icagenda.com – Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15_CVE-2026-48939

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in P...

icagenda.com iCagenda extension for Joomla 1.0.0-3.9.14 CVE
CRITICAL 9.5 CVE-2026-48909

Joomla Extension – joomshaper.com – PHP Object injection in SP LMS extension for Joomla < 4.1.4_CVE-2026-48909

SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker t...

joomshaper.net SP LMS extension for Joomla 1.0.0-4.1.3 CVE
CRITICAL 10 CVE-2026-48908

Joomla Extension – joomshaper.com – Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.12_CVE-2026-48908

A vulnerability in the SP Page Builder for Joomla allows the upload of arbitrary files for unauthenticated users, ultimately resulting in PHP code ...

joomshaper.net SP Page Builder extension for Joomla 1.0.0-6.6.1 CVE
MEDIUM 5.9 CVE-2026-12673

CVE-2026-12673_CVE-2026-12673

Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a secon...

liquidfiles liquidfiles CVE
CRITICAL 10 D4275D24-A482-

GumVulns_D4275D24-A482-561B-8402-1DE456184863

GumVulns A single-file PHP CLI that searches many vulnerability APIs in parallel and returns a normalized record for each hit: CVE id, description,...

N/A N/A GITHUBEXPLOIT
HIGH 8.6 3E4275D3-0547-

Exploit for Server-Side Request Forgery in Vercel Next.Js_3E4275D3-0547-519B-A6B4-38321844D41A

╔══════════════════════════════════════════════════════════════╗ ║ NextSSRF — CVE-2026-44578 Scanner & Exploit ║ ║ Next.js WebSocket Upgrade Handle...

N/A N/A GITHUBEXPLOIT
NONE AF15C141-8026-

sql-injection-vulnerability-scanner_AF15C141-8026-5A38-9333-A542B5316D04

...

N/A N/A GITHUBEXPLOIT