Archive // 2026-10

October 2026

Everything the feeds carried with a date in October 2026: still live, or dropped out of the rolling window since. Changes to a CVE's severity, score or exploited status are listed under it.

News 04 Oct 2026
Mistral AIProviderfirst seen 04 Oct 2026live
CVE 03 Oct 2026
CVE-2026-94539 The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to time-based SQL Injection via the 'sort_by' parameter in…
Medium 6.5first seen 04 Oct 2026live
CVE 03 Oct 2026
CVE-2026-94378 The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in…
Medium 6.4first seen 04 Oct 2026live
CVE 03 Oct 2026
CVE-2026-91108 The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to authorization bypass in all versions up to, and…
Medium 4.3first seen 04 Oct 2026live
CVE 02 Oct 2026
CVE-2026-94486 Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protocol…
Unscoredfirst seen 04 Oct 2026live
CVE 02 Oct 2026
CVE-2026-94485 Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol…
Unscoredfirst seen 04 Oct 2026live
CVE 01 Oct 2026
CVE-2026-96561 The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.0…
High 7.2first seen 04 Oct 2026live
CVE 01 Oct 2026
CVE-2026-51888 langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storage boundary.. The component…
Unscoredfirst seen 04 Oct 2026live
CVE 01 Oct 2026
CVE-2026-51886 langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is…
Unscoredfirst seen 04 Oct 2026live
CVE 01 Oct 2026
CVE-2026-51884 The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an…
Unscoredfirst seen 04 Oct 2026live
CVE 01 Oct 2026
CVE-2026-51883 The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal…
Unscoredfirst seen 04 Oct 2026live
CVE 01 Oct 2026
CVE-2026-51882 The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations…
Unscoredfirst seen 04 Oct 2026live
CVE 01 Oct 2026
CVE-2025-71427 Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by…
Medium 6.8first seen 04 Oct 2026live