Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44839
Total
3598
Critical
13323
High
13186
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-77079 | UNKNOWN | — | n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project role with a … | Aug 20, 2026 |
| CVE-2026-77077 | UNKNOWN | — | n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runner's prototype-freezing routine covers globalThis functions but not internal … | Aug 20, 2026 |
| CVE-2026-77076 | UNKNOWN | — | n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQL node. When a GraphQL request fails at the connection level, … | Aug 20, 2026 |
| CVE-2026-77075 | UNKNOWN | — | n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vulnerability in resource-locator field link preview rendering. The editor spliced the … | Aug 20, 2026 |
| CVE-2026-77074 | UNKNOWN | — | n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation that allows authenticated users to inject MVG … | Aug 20, 2026 |
| CVE-2026-77073 | UNKNOWN | — | n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an expression. Attackers with a … | Aug 20, 2026 |
| CVE-2026-77072 | UNKNOWN | — | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the Form node's completion page. The completion page applied its sandboxing Content-Security-Policy … | Aug 20, 2026 |
| CVE-2026-77071 | UNKNOWN | — | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update operations, which built … | Aug 20, 2026 |
| CVE-2026-77070 | UNKNOWN | — | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate operations, which parse the Query parameter … | Aug 20, 2026 |
| CVE-2026-77069 | UNKNOWN | — | n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential authorization-code-to-access-token exchange. While OAuth2 discovery and dynamic-client-registration requests use n8n's … | Aug 20, 2026 |
| CVE-2026-77068 | UNKNOWN | — | n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP node-schema loading. The loader … | Aug 20, 2026 |
| CVE-2026-74021 | HIGH | 7.5 | Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions. | Aug 20, 2026 |
| CVE-2026-74020 | HIGH | 7.5 | Unauthenticated Broken Access Control in Koji <= 2.2.1 versions. | Aug 20, 2026 |
| CVE-2026-74019 | HIGH | 7.1 | Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions. | Aug 20, 2026 |
| CVE-2026-74018 | CRITICAL | 9.9 | Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. | Aug 20, 2026 |
| CVE-2026-74016 | CRITICAL | 9.9 | Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions. | Aug 20, 2026 |
| CVE-2026-74014 | CRITICAL | 9.9 | Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions. | Aug 20, 2026 |
| CVE-2026-74013 | HIGH | 8.5 | Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. | Aug 20, 2026 |
| CVE-2026-74001 | CRITICAL | 9.8 | Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. | Aug 20, 2026 |
| CVE-2026-73998 | HIGH | 8.5 | Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. | Aug 20, 2026 |
| CVE-2026-73993 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | Aug 20, 2026 |
| CVE-2026-73992 | CRITICAL | 9.9 | Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. | Aug 20, 2026 |
| CVE-2026-73402 | MEDIUM | 6.5 | Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions. | Aug 20, 2026 |
| CVE-2026-68566 | CRITICAL | 9.3 | Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. | Aug 20, 2026 |
| CVE-2026-68564 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions. | Aug 20, 2026 |