| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions. |
| Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions. |
| Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. |
| Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. |
| HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing. |
| Unauthenticated Broken Access Control in Koji <= 2.2.1 versions. |
| Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions. |
| Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. |
| Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. |
| Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. |
| Subscriber Broken Authentication in Leyka <= 3.32.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions. |
| Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions. |
| Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. |
| Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. |
| Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions. |
| n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git node executed certain repository-local git configuration values without neutralizing them, so any subsequent Git node operation against a repository containing a malicious value would execute it as the n8n process user. This is not reachable through the Git node's own configuration controls and requires a separate file-write vulnerability elsewhere to plant the malicious value. |
| n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS) vulnerability in the Filter and Switch nodes, which compile user-supplied regex patterns with new RegExp() and execute them synchronously on the worker thread without complexity validation or execution timeout. A crafted regex pattern can block the worker for an extended period per data item processed, delaying other workflow executions on the same worker. |
| n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. When the node's Authentication parameter is set to expression mode, every authentication-gated credential selector is treated as active; if two credentials of different types are attached, the node enforces the allowed-domains policy of only the first credential while still attaching material from both. An authenticated user with workflow-authoring rights can thereby send a domain-restricted credential to an attacker-controlled endpoint, exfiltrating it with the leaked credential's permissions. |