Known Vulnerabilities for EP4 More Embeds by Dave Lavoie
Listed below are 10 of the newest known vulnerabilities associated with "EP4 More Embeds" by "Dave Lavoie".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-61454 json | The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ i... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2026-59695 json | Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-pa... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-59149 json | Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is confi... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-56340 json | vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorc... | Not Provided | 2026-06-20 | 2026-07-15 |
| CVE-2026-56124 json | phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to acc... | Not Provided | 2026-06-29 | 2026-07-14 |
| CVE-2026-55514 json | vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/... | Not Provided | 2026-07-06 | 2026-07-06 |
| CVE-2026-54431 json | In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains p... | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2026-52891 json | Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filename... | Not Provided | 2026-07-15 | 2026-07-17 |
| CVE-2026-52837 json | Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view ... | Not Provided | 2026-07-14 | 2026-07-21 |
| CVE-2026-50132 json | Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public end... | Not Provided | 2026-06-26 | 2026-06-29 |