CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2026-66672

    Last Modified: 21 Aug 2026

    Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.

    Published: 20 Aug 2026
    9.3
    Critical

    CVE-2026-66649

    Last Modified: 20 Aug 2026

    Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.

    Published: 20 Aug 2026
    6.5
    Medium

    CVE-2026-66647

    Last Modified: 21 Aug 2026

    Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-66616

    Last Modified: 20 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-66615

    Last Modified: 20 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-66614

    Last Modified: 21 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-66612

    Last Modified: 20 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-66611

    Last Modified: 20 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.

    Published: 20 Aug 2026
    9.3
    Critical

    CVE-2026-66609

    Last Modified: 21 Aug 2026

    Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-66607

    Last Modified: 24 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-66606

    Last Modified: 21 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-66605

    Last Modified: 21 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-66604

    Last Modified: 20 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.

    Published: 20 Aug 2026
    6.5
    Medium

    CVE-2026-66601

    Last Modified: 20 Aug 2026

    Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.

    Published: 20 Aug 2026
    9.1
    Critical

    CVE-2026-66600

    Last Modified: 20 Aug 2026

    Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-66598

    Last Modified: 21 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-66597

    Last Modified: 20 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.

    Published: 20 Aug 2026
    5.9
    Medium

    CVE-2026-66595

    Last Modified: 20 Aug 2026

    Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.

    Published: 20 Aug 2026
    8.5
    High

    CVE-2026-66594

    Last Modified: 21 Aug 2026

    Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.

    Published: 20 Aug 2026
    9.3
    Critical

    CVE-2026-66593

    Last Modified: 21 Aug 2026

    Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.

    Published: 20 Aug 2026
    9.3
    Critical

    CVE-2026-66592

    Last Modified: 20 Aug 2026

    Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-66590

    Last Modified: 21 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.

    Published: 20 Aug 2026
    6.6
    Medium

    CVE-2026-66586

    Last Modified: 21 Aug 2026

    Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2026-66583

    Last Modified: 21 Aug 2026

    Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-66582

    Last Modified: 20 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-66581

    Last Modified: 21 Aug 2026

    Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.

    Published: 20 Aug 2026
    8.1
    High

    CVE-2026-28150

    Last Modified: 20 Aug 2026

    Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.

    Published: 20 Aug 2026
    6.5
    Medium

    CVE-2025-53999

    Last Modified: 20 Aug 2026

    Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.

    Published: 20 Aug 2026
    9.8
    Critical

    CVE-2025-15689

    Last Modified: 20 Aug 2026

    Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.

    Published: 20 Aug 2026
    9.3
    Critical

    CVE-2025-15688

    Last Modified: 20 Aug 2026

    Unauthenticated SQL Injection in Capella <= 2.5.5 versions.

    Published: 20 Aug 2026
    8.1
    High

    CVE-2025-15637

    Last Modified: 21 Aug 2026

    Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.

    Published: 20 Aug 2026
    7.5
    High

    CVE-2026-74021

    Last Modified: 21 Aug 2026

    Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.

    Published: 20 Aug 2026
    8.1
    High

    CVE-2026-77176

    Last Modified: 21 Aug 2026

    A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content, potentially exposing confidential information or enabling the acceptance of attacker-controlled input.

    Published: 20 Aug 2026
    6.3
    Medium

    CVE-2026-77085

    Last Modified: 1 Sept 2026

    n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent requests to the user-supplied API URL using a raw HTTP client that did not route through n8n's centralized SSRF protection. On instances with N8N_SSRF_PROTECTION_ENABLED=true, an authenticated user with permission to create SearXNG credentials and configure a personal agent could set the API URL to an internal host, causing the n8n server to connect to that host and return the response content through the Agent chat output.

    Published: 20 Aug 2026
    7.7
    High

    CVE-2026-77084

    Last Modified: 1 Sept 2026

    n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git node executed certain repository-local git configuration values without neutralizing them, so any subsequent Git node operation against a repository containing a malicious value would execute it as the n8n process user. This is not reachable through the Git node's own configuration controls and requires a separate file-write vulnerability elsewhere to plant the malicious value.

    Published: 20 Aug 2026
    6
    Medium

    CVE-2026-77083

    Last Modified: 1 Sept 2026

    n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM sandbox did not freeze the sandbox's Function.prototype, allowing an authenticated user with the ability to create and execute workflows to pollute it from within a Code node execution and recover a reference to the host's globalThis, resulting in a sandbox escape. The full exploit chain additionally depends on specific modules being available as allowlisted imports in the deployment's configuration. The issue is fixed in versions 1.123.69, 2.33.4, and 2.34.1.

    Published: 20 Aug 2026
    5.3
    Medium

    CVE-2026-77082

    Last Modified: 1 Sept 2026

    n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS) vulnerability in the Filter and Switch nodes, which compile user-supplied regex patterns with new RegExp() and execute them synchronously on the worker thread without complexity validation or execution timeout. A crafted regex pattern can block the worker for an extended period per data item processed, delaying other workflow executions on the same worker.

    Published: 20 Aug 2026
    5.1
    Medium

    CVE-2026-77081

    Last Modified: 1 Sept 2026

    n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. When the node's Authentication parameter is set to expression mode, every authentication-gated credential selector is treated as active; if two credentials of different types are attached, the node enforces the allowed-domains policy of only the first credential while still attaching material from both. An authenticated user with workflow-authoring rights can thereby send a domain-restricted credential to an attacker-controlled endpoint, exfiltrating it with the leaked credential's permissions.

    Published: 20 Aug 2026
    8.7
    High

    CVE-2026-77080

    Last Modified: 1 Sept 2026

    n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which passes free-form Execute Query input, including client-side commands, directly to the Snowflake SDK without applying n8n's file-access restrictions. An authenticated user with usable Snowflake credentials can upload a local file from the n8n host or overwrite an existing file with a staged one.

    Published: 20 Aug 2026
    7.4
    High

    CVE-2026-77079

    Last Modified: 1 Sept 2026

    n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project role with a reassignment target, the code validated only that the target role existed and was project-scoped, performing no project-level authorization check. A user holding only the narrow role:manageProject global scope could delete any custom project role in use on the instance and reassign its holders (including themselves) to the built-in project:admin role, gaining full administrative control of projects they had no legitimate access to.

    Published: 20 Aug 2026
    7.2
    High

    CVE-2026-77077

    Last Modified: 1 Sept 2026

    n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runner's prototype-freezing routine covers globalThis functions but not internal module constructors such as EventEmitter, allowing an authenticated user with Code node access to exploit prototype pollution to execute arbitrary commands within the runner container. Because the polluted prototype is a process-wide object, the corruption persists across other tenants' Code node executions on the same shared runner. On v1.x instances without task runners enabled, Code node JavaScript runs directly in the main n8n process, where the impact could be higher.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-77076

    Last Modified: 1 Sept 2026

    n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQL node. When a GraphQL request fails at the connection level, the node re-throws the underlying HTTP client error unchanged instead of wrapping it in n8n's standard error type. That error contains the live request's headers, including a decrypted credential secret, which the execution engine persists verbatim. Any authenticated user able to read the resulting execution can retrieve the decrypted credential secret from the stored run data.

    Published: 20 Aug 2026
    8.4
    High

    CVE-2026-77075

    Last Modified: 1 Sept 2026

    n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vulnerability in resource-locator field link preview rendering. The editor spliced the field's stored value directly into the node type's URL template without checking for expression syntax. An authenticated member can store a malicious value so that when another user opens the affected node in the editor, the injected expression is evaluated as JavaScript in the victim's authenticated session (cross-user script execution).

    Published: 20 Aug 2026
    6
    Medium

    CVE-2026-77074

    Last Modified: 1 Sept 2026

    n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation that allows authenticated users to inject MVG primitives. Attackers can craft malicious text values to issue blind outbound HTTP requests to arbitrary addresses or access local files.

    Published: 20 Aug 2026
    5.3
    Medium

    CVE-2026-77073

    Last Modified: 1 Sept 2026

    n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an expression. Attackers with a valid MCP Bearer API key and knowledge of a target credential ID can persist unauthorized cross-project credential references on workflows in different projects.

    Published: 20 Aug 2026
    8.4
    High

    CVE-2026-77072

    Last Modified: 1 Sept 2026

    n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the Form node's completion page. The completion page applied its sandboxing Content-Security-Policy only when respondWith was not set to 'redirect', but responseText was always rendered as raw HTML. An authenticated member could set respondWith to 'redirect' via an expression while keeping responseText populated, causing the completion page to serve unsanitized HTML and script from the n8n origin. Any visitor who submitted the resulting public form would have that script execute same-origin with their session.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-77071

    Last Modified: 1 Sept 2026

    n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update operations, which built filter queries by concatenating an expression-bindable value without escaping. An attacker could inject a condition that widened the filter to match every row, turning an intended single-row operation into full-table disclosure, deletion, or modification.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-77070

    Last Modified: 1 Sept 2026

    n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate operations, which parse the Query parameter as JSON after expression resolution without sanitizing MongoDB operators. An attacker who can influence the resolved query (e.g., via externally-controlled data) can inject operators such as $ne or $where, turning an intended single-document lookup into full-collection disclosure, full-collection deletion, or other operations on the database server.

    Published: 20 Aug 2026
    2.3
    Low

    CVE-2026-77069

    Last Modified: 1 Sept 2026

    n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential authorization-code-to-access-token exchange. While OAuth2 discovery and dynamic-client-registration requests use n8n's SSRF-protected HTTP client, the token exchange uses a separate client with no SSRF guard. A user with credential-creation permissions can set the access-token URL to an internal address and complete the OAuth2 flow, causing n8n to send a fixed-shape token-exchange POST to that target and reflect its response body back to the attacker (limited to what the target returns to this specific request).

    Published: 20 Aug 2026
    8.7
    High

    CVE-2026-77068

    Last Modified: 1 Sept 2026

    n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP node-schema loading. The loader derives a node's schema module path directly from the attacker-supplied node type string without validating path-traversal sequences. An authenticated user with global:member privileges can reference malicious files via path traversal, causing code execution in the n8n main process.

    Published: 20 Aug 2026