Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2026-56274

Flowise – Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess_CVE-2026-56274

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validat...

Flowise Flowise CVE
MEDIUM 5.3 CVE-2026-56263

Crawl4AI – Stored Cross-Site Scripting in Monitor Dashboard_CVE-2026-56263

Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl URLs and error messages via ...

Crawl4AI Crawl4AI CVE
CRITICAL 9.2 CVE-2026-56258

Crawl4AI – Arbitrary File Write via output_path Symlink and TOCTOU_CVE-2026-56258

Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to w...

Crawl4AI Crawl4AI 0.8.8 CVE
HIGH 8.7 CVE-2026-56248

Capgo – Unauthenticated Denial-of-Service via audit_logs RLS Policy_CVE-2026-56248

Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from the audit_logs table's Row-L...

Cap-go capgo CVE
HIGH 8.6 CVE-2026-56243

Capgo – Hashed API Key Enforcement Bypass via PostgREST/RLS Plane_CVE-2026-56243

Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext API keys through the capgkey...

Capgo Capgo CVE
MEDIUM 6.9 CVE-2026-56234

Capgo – Password Spraying via Public-Key Accessible Credential Validation Endpoint_CVE-2026-56234

Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validate_password_compliance endpoint that i...

Capgo Capgo CVE
HIGH 8.7 CVE-2026-56225

Capgo – Authorization Bypass in API Key Management via App-Limited Keys_CVE-2026-56225

Capgo before 12.128.2 contains an authorization bypass vulnerability in its public API key management handlers (get/put/delete/post). API keys crea...

Capgo Capgo CVE
HIGH 8.6 CVE-2026-56222

Capgo – Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_bindings_CVE-2026-56222

Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to verify app_id ownership during ap...

Capgo Capgo CVE
HIGH 8.7 CVE-2026-54892

Plug: quadratic-time decoding of nested query/body parameters enables denial of service_CVE-2026-54892

Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause denial of service. Plug.Co...

elixir-plug plug 1.15.0 CVE
MEDIUM 6.4 CVE-2026-4610

ProfileGrid <= 5.9.9.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content_CVE-2026-4610

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_messag...

metagauss ProfileGrid – User Profiles, Groups and Communities CVE