Known Vulnerabilities for La-forge-mcp by MonomythDevelopment
Listed below are 10 of the newest known vulnerabilities associated with "La-forge-mcp" by "MonomythDevelopment".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-92912 json | AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in ... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-92749 json | SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-91017 json | The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming paym... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-90945 json | Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration ... | Not Provided | 2026-09-14 | 2026-09-16 |
| CVE-2026-90942 json | Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/ge... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-90893 json | MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController. The actions setTheme, setHomeP... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-90451 json | An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies... | Not Provided | 2026-09-11 | 2026-09-14 |
| CVE-2026-90448 json | A deployment mode intended to expose only read access to stored data proxies a set of application programming interface route... | Not Provided | 2026-09-11 | 2026-09-14 |
| CVE-2026-89026 json | The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 J... | Not Provided | 2026-09-15 | 2026-09-17 |
| CVE-2026-88871 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forger... | Not Provided | 2026-09-10 | 2026-09-15 |