Known Vulnerabilities for WC Marketplace by MultiVendorX
Listed below are 10 of the newest known vulnerabilities associated with "WC Marketplace" by "MultiVendorX".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56397 json | SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious pack... | Not Provided | 2026-06-21 | 2026-06-24 |
| CVE-2026-56395 json | SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious pack... | Not Provided | 2026-06-21 | 2026-06-22 |
| CVE-2026-55570 json | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name,... | Not Provided | 2026-06-24 | 2026-06-25 |
| CVE-2026-55413 json | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agent... | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-54838 json | Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions. | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-54070 json | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, renderPackageREADME in kernel/bazaar/readme.go... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-53810 json | OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect l... | Not Provided | 2026-06-11 | 2026-06-12 |
| CVE-2026-48027 json | Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-47277 json | Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from fil... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-45375 json | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) render... | Not Provided | 2026-05-14 | 2026-05-16 |