Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2026-56396

phpMyFAQ – Privilege Escalation via Missing Authorization in editUser() and updateUserRights()_CVE-2026-56396

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated admini...

phpMyFAQ phpMyFAQ CVE
HIGH 7.1 CVE-2026-56394

Craft CMS – Authenticated Path Traversal in assets/icon Extension Parameter_CVE-2026-56394

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not va...

craftcms cms 4.0.0-RC1 CVE
HIGH 8.6 CVE-2026-56382

Craft CMS – Remote Code Execution via Missing Config Sanitization in FieldsController_CVE-2026-56382

Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and

craftcms cms 5.5.0 CVE
HIGH 8.7 CVE-2026-56253

Capgo – Unauthenticated Organization Member Email Disclosure via get_org_members RPC_CVE-2026-56253

Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function that allows unauthenticated atta...

Capgo Capgo CVE
HIGH 7 CVE-2026-56251

Capgo – Privilege Escalation via Broken Row Level Security in org_users_CVE-2026-56251

Capgo before 12.128.2 contains a broken row level security policy in the org_users table that allows authenticated users to elevate privileges from...

Capgo Capgo CVE
HIGH 8.7 CVE-2026-56242

Capgo – Unauthenticated API Key Validity Oracle and User Identity Disclosure via get_identity_apikey_only RPC_CVE-2026-56242

Capgo before 12.128.2 contains an unauthenticated security definer RPC function get_identity_apikey_only that returns the owning user_id for suppli...

Capgo Capgo CVE
HIGH 7.2 CVE-2026-56239

Capgo – Privilege Escalation via SECURITY DEFINER Function apply_usage_overage_CVE-2026-56239

Capgo before 12.128.2 contains a potential privilege escalation vulnerability in the public.apply_usage_overage SECURITY DEFINER function, which pe...

Capgo Capgo CVE
HIGH 7.1 CVE-2026-56229

Capgo – Cross-App Build Job Access via app_id/job_id Mismatch in /build/status and /build/logs_CVE-2026-56229

Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endpoints that allows attackers to access...

Capgo Capgo CVE
HIGH 7.6 CVE-2025-71378

picklescan – Remote Code Execution via Undetected cProfile.runctx in Pickle Files_CVE-2025-71378

picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code...

picklescan picklescan CVE
HIGH 7.6 CVE-2025-71357

picklescan – Arbitrary Code Execution via Undetected idlelib.pyshell.ModifiedInterpreter.runcommand_CVE-2025-71357

picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers c...

picklescan picklescan CVE