Known Vulnerabilities for Media From Ftp by Riverforest-wp
Listed below are 1 of the newest known vulnerabilities associated with "Media From Ftp" by "Riverforest-wp".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65896 json | Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POS... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65054 json | MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media metad... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-64823 json | Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_media... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-63096 json | Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause t... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-62415 json | The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets. | Not Provided | 2026-07-21 | 2026-07-21 |
| CVE-2026-62216 json | OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or config... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-62210 json | OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read att... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-61457 json | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controlle... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-61456 json | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1/medi... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-61448 json | Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8... | Not Provided | 2026-07-11 | 2026-07-13 |