Known Vulnerabilities for RPG MAKER MZ by Gotcha Gotcha Games Inc.
Listed below are 10 of the newest known vulnerabilities associated with "RPG MAKER MZ" by "Gotcha Gotcha Games Inc.".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66616 json | Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions. | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-65565 json | Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-57663 json | Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions. | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-57361 json | Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions. | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2026-56254 json | In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to e... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-56137 json | RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads a spe... | Not Provided | 2026-06-30 | 2026-06-30 |
| CVE-2026-39502 json | Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-28177 json | Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-16977 json | The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is subst... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-15993 json | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL ... | Not Provided | 2026-08-15 | 2026-08-17 |