|
1421
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel.
|
CWE-79
Cross-site Scripting
|
CVE-2026-50709
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1422
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component.
|
CWE-79
Cross-site Scripting
|
CVE-2026-50710
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1423
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component.
|
CWE-79
Cross-site Scripting
|
CVE-2026-50711
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1424
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component
|
CWE-79
Cross-site Scripting
|
CVE-2026-50712
|
2026-06-25 23:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1425
|
8.7 |
HIGH
Network
|
-
|
-
|
Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitrary victim accounts based on email match without v…
|
CWE-287
Improper Authentication
|
CVE-2026-56223
|
2026-06-25 23:03 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1426
|
8.8 |
HIGH
Network
|
-
|
-
|
Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited-key-id header in middlewareKey function. Attackers can bypass subkey scope res…
|
CWE-863
Incorrect Authorization
|
CVE-2026-56232
|
2026-06-25 23:03 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1427
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are exposed in frontend requests, and the backend fails to validate that keys are se…
|
CWE-287
Improper Authentication
|
CVE-2026-56237
|
2026-06-25 23:03 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1428
|
7.1 |
HIGH
Network
|
-
|
-
|
Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient row-level security policies on the webhooks table. Attackers can retrieve the web…
|
CWE-200
Information Exposure
|
CVE-2026-56244
|
2026-06-25 23:03 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1429
|
8.2 |
HIGH
Network
|
-
|
-
|
Supabase Capgo before 12.128.2 contains an authorization bypass vulnerability in the SECURITY DEFINER record_build_time RPC function that allows unauthenticated attackers to insert arbitrary build-ti…
|
CWE-269
Improper Privilege Management
|
CVE-2026-56245
|
2026-06-25 23:03 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1430
|
7.1 |
HIGH
Network
|
-
|
-
|
Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. Sensitive Organization (ORG) management API endpoints (e.g., editing organization details, inviting users) do …
|
CWE-602
Client-Side Enforcement of Server-Side Security
|
CVE-2026-56256
|
2026-06-25 23:03 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|