💬 Discourse Rich Text Editor Flaw Enables Stored XSS
Discourse administrators should upgrade to a fixed release promptly, especially on communities where untrusted users can submit chat content.
CVE-2026-72730 is a stored cross-site scripting vulnerability in the Discourse Rich Text Editor, where chat-transcript usernames could be rendered as HTML. Discourse versions prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0 are affected. The vulnerability is rated HIGH with CVSS 8.7.
🔗 Read more 🔗
Source: NVD
🔐 Multicluster Global Hub Flaw Lets Compromised Hubs Falsify Data
Organizations running multicluster-global-hub should prioritize remediation, particularly where managed hubs or Kafka credentials could be exposed. A compromised hub can become a stepping stone for corrupting data associated with other hubs.
CVE-2026-71576 affects the manager component of multicluster-global-hub, which fails to properly validate the source identity of CloudEvents received through Kafka status topics. An attacker who has compromised a managed hub and obtained its Kafka client certificate can impersonate other hubs and falsify or delete their compliance, inventory, and cluster-health data. The vulnerability is rated HIGH with CVSS 8.5.
🔗 Read more 🔗
Source: NVD
🤖 Malicious Git Config Can Trigger Code Execution in Goose Review
Developers using goose on untrusted or third-party repositories should upgrade to 1.44.0 immediately. Until patched, merely reviewing a malicious repository can expose local files, environment secrets, and provider API keys.
CVE-2026-72718 affects goose before version 1.44.0 and allows a malicious repository to execute arbitrary commands when the ‘goose review’ command invokes Git. An attacker-controlled .git/config can abuse Git’s fsmonitor setting, causing code to run before any model call, prompt, trust check, or tool approval and outside goose’s sandbox or permission model. The vulnerability is rated HIGH with CVSS 7.0.
🔗 Read more 🔗
Source: NVD
💥 SPIP SQLite Installations Exposed to Authenticated Command Execution
SPIP administrators using SQLite should upgrade to 4.4.18 or later urgently. Because editor-level accounts are sufficient for command execution, treat compromised or broadly assigned editor credentials as a serious exposure.
CVE-2026-66738 is a code injection vulnerability affecting SPIP before 4.4.18 when backed by SQLite. An authenticated attacker with at least editor privileges can exploit improperly handled array input in the navigation endpoint to execute arbitrary operating-system commands in the web server process. MySQL-backed installations are not affected, and the vulnerability is rated HIGH with CVSS 8.8.
🔗 Read more 🔗
Source: NVD
☠️ Malicious use-context-selector Commits Compromised Developer Machines
Anyone who ran ‘npm install’ against an affected checkout on or after 2026-05-18 15:57:18 should treat the workstation as compromised, rotate every reachable credential, audit account activity, and remove contaminated clones. This is incident-response territory, not just a routine package update.
CVE-2026-48158 concerns malicious commits temporarily present on the default branch of the React package use-context-selector, where a postinstall script downloaded and executed attacker-controlled JavaScript during ‘npm install’. The affected commits were removed, but local clones, forks, and direct-SHA references can still contain them and remain dangerous; the package itself was not published to npm. The issue is rated CRITICAL with CVSS 9.3, and affected developer machines should be assumed fully compromised.
🔗 Read more 🔗
Source: NVD
🗄️ Discourse Data Explorer Parameters Enable Arbitrary SQL Reads
Discourse sites using Data Explorer should upgrade to 2026.1.7, 2026.6.2, 2026.7.1, or 2026.8.0-latest.1 as soon as possible. Sites sharing queries with non-staff groups should treat this as particularly urgent because sensitive database contents may be readable.
CVE-2026-72731 affects Discourse Data Explorer and allows users permitted to run parameterized queries, including some non-staff group members, to escape intended query parameters and execute arbitrary SQL. Recursive parameter interpolation and declarations embedded in SQL comments can expose any database table, although queries execute within a read-only transaction and cannot modify data. The vulnerability is rated HIGH with CVSS 7.1.
🔗 Read more 🔗
Source: NVD
🔑 XWiki LiveTable Weakness Can Leak Password Hashes Bit by Bit
XWiki operators should move to 18.0.0RC1, 17.10.13, 17.4.9, 16.10.17, or another fixed release promptly. Where immediate upgrades are impossible, apply the vendor-described patch to XWiki.LiveTableResultsMacros.
CVE-2026-48048 affects XWiki Platform from version 6.2.1 up to the listed fixed releases and results from an incomplete earlier security patch. Modified LiveTableResults parameters can reveal password salts and hashes one bit at a time, with the full value recoverable in 768 requests. The vulnerability is rated HIGH with CVSS 7.5.
🔗 Read more 🔗
Source: NVD
🚨 Metacat Path Traversal Exposes Sensitive Server Files Without Login
Any reachable Metacat deployment older than 3.0.0 should be treated as high priority because exploitation requires only a crafted GET request and verified proof-of-concept exploits exist. Upgrade to 3.0.0 or later, or immediately disable or tightly restrict the legacy 1.x API servlets and restart the hosting service.
CVE-2026-47754 is an unauthenticated path traversal vulnerability affecting Metacat 2.x through 2.19.1 and all 1.x versions through the legacy 1.x API. A remote attacker can manipulate the archiveEntryName parameter to read any file accessible to the Tomcat process, potentially exposing credentials, private keys, embargoed research data, and other sensitive system information. Proof-of-concept exploits have been demonstrated and verified, and the vulnerability is rated CRITICAL with CVSS 9.3.
🔗 Read more 🔗
Source: NVD
👤 Prospero Flow CRM Authorization Bypass Exposes Cross-Company Contacts
Prospero Flow CRM customers should upgrade to 5.4.8 or later quickly, especially in multi-tenant environments. Review logs for unusual contact exports or modifications across company boundaries.
CVE-2026-19433 affects the contact management component in Roskus Prospero Flow CRM before 5.4.8. Authenticated users from one company can use another contact’s numeric identifier to overwrite that contact’s information or download their personal data as a vCard because record lookups are not restricted to the user’s company. The vulnerability is rated HIGH with CVSS 8.6.
🔗 Read more 🔗
Source: NVD
💉 ReadyEcommerce SQL Injection Can Expose the Entire Database
Internet-facing ReadyEcommerce installations should be upgraded to 4.5.2 or later immediately. The combination of unauthenticated access, full database extraction, and a root database connection makes this a critical patching priority.
CVE-2026-63106 is an unauthenticated SQL injection vulnerability affecting ReadyEcommerce before 4.5.2. The products API concatenates the rating parameter directly into a MySQL HAVING clause, enabling time-based blind SQL injection that can extract database contents including credentials and administrator password hashes. Because the database connection runs as root, additional filesystem access may also be possible; the vulnerability is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD
📄 OpenSign Flaw Lets Anyone Decline Documents and Forge Attribution
OpenSign operators on 2.37.0 or earlier should remediate urgently, particularly where signature workflows carry legal or compliance significance. The flaw can terminate workflows and falsify evidentiary records without authentication.
CVE-2026-72692 is a missing authorization vulnerability affecting OpenSignLabs opensignserver through 2.37.0. An unauthenticated remote attacker can invoke the declinedoc cloud function to irreversibly decline an accessible in-flight document and falsely attribute the action to an arbitrary user. The vulnerability is rated HIGH with CVSS 7.5.
🔗 Read more 🔗
Source: NVD
🔓 OpenSign Authentication Bypass Can Mint File Access Tokens
OpenSign deployments running 2.37.0 or earlier should prioritize remediation because unauthenticated attackers may gain signed access to stored files. Until fixed, restrict exposure of the affected cloud function and investigate unexpected signed-URL activity.
CVE-2026-72691 is an authentication bypass vulnerability affecting OpenSignLabs opensignserver through 2.37.0. By supplying any docId value to the getsignedurl cloud function, an unauthenticated remote attacker can bypass the normal authentication check and mint MASTER_KEY-signed access tokens for arbitrary stored files. The vulnerability is rated HIGH with CVSS 7.5.
🔗 Read more 🔗
Source: NVD