Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 11 July 2026

RSS

239 vulnerabilities published on 11 July 2026

Severity:
PraisonAI CodeAgent Python Code Execution Risk
CVE-2026-61447
PraisonAI versions prior to 1.6.78 are at risk of attackers executing malicious code on the host system. This is due to a lack of validation and restrictions on Python code generated by the Large Lang...
10.0
Joomla RSFiles Extension Allows Unauthenticated File Upload
CVE-2026-57827
The RSFiles extension in Joomla allows unauthorized users to upload any type of file, including executable files. This can lead to hackers gaining full control over the website. Update to the latest v...
10.0
PraisonAI AICoder Component Allows File Writing and Command Execution
CVE-2026-61445
PraisonAI's AICoder component has a security flaw that allows attackers to write files anywhere on the system and run commands with high-level permissions through the chat interface. This means sensit...
9.4
PraisonAI SQL Injection via Unvalidated Vector Dimension
CVE-2026-60090 GHSA-wf65-4jjx-q444
PraisonAI versions prior to 4.6.78 are at risk of SQL injection attacks. An attacker can manipulate the dimension value passed to the database, potentially executing malicious SQL commands. To protect...
9.9
PraisonAI before 4.6.78 allows SQL/CQL injection
CVE-2026-60090
PraisonAI's knowledge-store in versions before 4.6.78 fails to check user input, allowing malicious users to inject SQL or Cassandra Query Language (CQL) code. This could potentially allow them to acc...
9.3
rootio-pyOpenSSL: Unauthorized access to sensitive data
ROOT-APP-PYPI-CVE-2026-27459
The rootio-pyOpenSSL package allows unauthorized access to sensitive data. This is a serious security risk because attackers could potentially steal or manipulate confidential information. Root has re...
9.8
PraisonAI before 4.6.78 Arbitrary File Write and Command Execution
CVE-2026-61445 GHSA-9mp3-24cc-77mg
PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attacker...
9.4
ImageMagick before 7.1.2-19 allows attackers to read sensitive data
CVE-2026-56372
ImageMagick, a popular image processing software, has a security issue that could allow attackers to access sensitive information. This issue affects versions of ImageMagick prior to 7.1.2-19. To stay...
4.8
Debian: Unpatched Kernel Allows Local Privilege Escalation
DEBIAN-CVE-2026-56372
A critical vulnerability in the Debian Linux kernel allows an attacker with local access to gain elevated privileges on a system. This can lead to unauthorized access to sensitive data and system cont...
9.1
Joomla Phoca Downloads RSFiles Component Allows Malicious File Upload
CVE-2026-57828
The Joomla Phoca Downloads extension's RSFiles component has a security issue that allows a registered user to upload malicious files. This could allow an attacker to take full control of the website,...
9.0
Genolve WordPress Plugin: Unauthorized Data Modification Possible
CVE-2026-1359
The Genolve plugin for WordPress allows attackers with Contributor-level access to modify certain settings, potentially enabling user registration and giving attackers administrator privileges. This a...
8.8
Code Engine <= 0.3.5 - Malicious Code Can Be Run
CVE-2025-6784
The Code Engine plugin for WordPress allows authenticated users with Contributor-level access to run malicious code on the server. This can lead to unauthorized actions and data breaches. Update to ve...
8.8
Essential Addons for Elementor <= 6.6.10 - Attackers can steal admin passwords
CVE-2026-15155
A security issue in Essential Addons for Elementor affects WordPress sites. If an attacker with some level of access logs in, they can steal the password of the site administrator. To stay safe, updat...
8.8
The Swiss Toolkit For WP plugin on WordPress allows unauthorized file uploads
CVE-2026-2354
The Swiss Toolkit For WP plugin for WordPress has a security flaw that allows attackers to upload any type of file on a site, potentially allowing them to execute malicious code. This affects all vers...
8.8
WordPress Simple JWT Login Plugin Allows Attackers to Escalate Privileges
CVE-2026-14262
A security flaw in the WordPress Simple JWT Login Plugin allows attackers to bypass authentication and gain administrator privileges. This affects all versions of the plugin up to 3.6.6. To stay secur...
8.8
WP Ultimate CSV Importer plugin allows attackers to run code on server
CVE-2026-13353
The WP Ultimate CSV Importer plugin for WordPress has a security flaw that allows attackers with basic access to run malicious code on your website. This means they can potentially steal data, delete ...
8.8
WP Grid Builder <= 2.3.3: Elevated Privileges for Subscribers
CVE-2026-13756
The WP Grid Builder plugin for WordPress allows attackers with Subscriber-level access to gain Administrator privileges. This is a serious security risk, as it could allow unauthorized users to make c...
8.8
PraisonAI before 1.7.3 allows unauthenticated access to chat data
CVE-2026-61426
PraisonAI, a chat software, has a default setting that lets anyone access its data without a password. This means that hackers can read and manipulate chat conversations and system prompts. To fix thi...
8.8
PraisonAI versions before 1.6.78 allow unauthorized access to internal services
CVE-2026-61429
PraisonAI versions before 1.6.78 contain a security flaw that could allow an attacker to access internal services within your organization. This is a serious issue because it could allow an attacker t...
8.4
PraisonAI AgentMail before 4.6.78 allows message spoofing via webhook
CVE-2026-61428 GHSA-qj9c-59p6-8cgx
PraisonAI AgentMail versions before 4.6.78 have a security issue that lets attackers send fake emails using other people's email addresses. This can be exploited by sending a special type of message t...
8.4
Important: Linux Kernel Update Fixes Security Risks
RLSA-2026:36018
This update addresses multiple security vulnerabilities in the Linux kernel, which could allow attackers to access sensitive information, escalate privileges, or cause a system crash. Affected systems...
8.4
Microsoft Edge (Chromium-based) Can Execute Unwanted Code Remotely
CVE-2026-58281
If not updated, Microsoft Edge users may be at risk of hackers executing malicious code on their devices without permission. This is a serious security risk because it allows attackers to take control...
8.3
Grav before 2.0.4 Leaks Server Information to Unauthenticated Users
CVE-2026-61454 GHSA-pfjq-chp8-3vgh
If you use Grav before version 2.0.4, an attacker can see information about your server without needing a password. This could help the attacker figure out how to target your specific setup and potent...
8.3
PraisonAI versions before 4.6.78 allow critical threats to pass through
CVE-2026-61439 GHSA-fj8f-m44g-c479
PraisonAI versions prior to 4.6.78 are not blocking high-risk threats as intended, allowing attackers to potentially extract sensitive information or execute unauthorized actions. This could lead to s...
8.3
Capgo - Unauthenticated Disclosure of Sensitive API Key Details
CVE-2026-56303 GHSA-2xjq-h43m-592f
Capgo versions before 12.128.2 allow attackers to retrieve sensitive information about API keys without authentication. This could lead to unauthorized access to user data or systems. Update to versio...
8.3