Common Vulnerabilities and Exposures (CVE)

CVE-2026-47409

Jul 21, 2026 17:21:30 UTC

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling owner lockout. The `DELETE /workspaces/{workspace_id}/members/{user_id}` endpoint is gated on...

CVE-2026-47410

Jul 21, 2026 17:20:55 UTC

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal `"dev-secret-change-me"` when ...

CVE-2026-47411

Jul 21, 2026 17:20:43 UTC

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling workspace metadata + settings tampering. The `PATCH /workspaces/{workspace_id}` endpoint is g...

CVE-2026-47412

Jul 21, 2026 17:20:33 UTC

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE /workspaces/{workspace_id}` endpoint is gated only by `requir...

CVE-2026-47413

Jul 21, 2026 17:20:22 UTC

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspace_id}/members` endpoint is gated only by...

CVE-2026-47414

Jul 21, 2026 17:19:34 UTC

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. Five label endpoints — `PATCH /workspaces/{workspace_id}/labels/{label_id}`, `DELETE .../...

CVE-2026-47415

Jul 21, 2026 17:19:22 UTC

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The issue CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/issues/{issue_...

CVE-2026-47416

Jul 21, 2026 17:19:11 UTC

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` endpoint is gated by `req...

CVE-2026-64824

Jul 21, 2026 17:19:07 UTC

Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry c...

CVE-2026-24232

Jul 21, 2026 17:19:03 UTC

NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

CVE-2026-60026

Jul 21, 2026 17:16:41 UTC

The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in element content, that got executed via view-cache include(). Requir...

CVE-2026-60029

Jul 21, 2026 17:16:33 UTC

The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS vulnerability. Authenticated builder users could break out of id/class fields that render for public users.

CVE-2026-60031

Jul 21, 2026 17:16:27 UTC

The Joomla extension Quix Page Builder Pro is vulnerable to an information disclosure. Raw exceptions reflected in AJAX handler responses.

CVE-2026-61900

Jul 21, 2026 17:16:19 UTC

The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.

CVE-2026-62414

Jul 21, 2026 17:16:12 UTC

The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.