Known Vulnerabilities for LH Email by Shawfactor
Listed below are 10 of the newest known vulnerabilities associated with "LH Email" by "Shawfactor".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-57632 json | Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions. | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-56785 json | FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields... | Not Provided | 2026-06-23 | 2026-06-24 |
| CVE-2026-56338 json | Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verificatio... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-56310 json | Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that allows o... | Not Provided | 2026-06-24 | 2026-06-25 |
| CVE-2026-56267 json | Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoint tha... | Not Provided | 2026-06-20 | 2026-06-22 |
| CVE-2026-56253 json | Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function that allow... | Not Provided | 2026-06-21 | 2026-06-23 |
| CVE-2026-56242 json | Capgo before 12.128.2 contains an unauthenticated security definer RPC function get_identity_apikey_only that returns the own... | Not Provided | 2026-06-21 | 2026-06-22 |
| CVE-2026-56223 json | Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows a... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-56215 json | Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, which th... | Not Provided | 2026-06-20 | 2026-06-24 |
| CVE-2026-56081 json | Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a... | Not Provided | 2026-06-19 | 2026-06-22 |