9 vulnerabilities across 3 products scored HIGH or above on June 23, 2026.
- ๐ HIGH: 9
๐ [HIGH] gogs.io/gogs
6 CVEs | CVSS 3.1: 10.0 | AAS 11.8
cpe:2.3:a:gogs.io:gogs:*:*:*:*:*:*:*:*
Gogs, the self-hosted Git service from gogs.io, is affected by six vulnerabilities, including at least one critical-severity issue carrying a CVSS score of 10.0. The most severe flaw allows an attacker to exploit path traversal in organization names to write repositories to arbitrary filesystem locations, ultimately achieving remote code execution by overwriting Git hook configurations. Security teams running self-hosted Gogs instances should treat this as an urgent priority, review the vendor advisory at the linked GitHub Security Advisory page, and apply patches or mitigations as soon as they become available.
- ๐ CVE-2026-52813 (CVSS 3.1: 10.0)
- ๐ CVE-2026-52806 (CVSS 3.1: 9.9)
- ๐ CVE-2026-52811 (CVSS 3.1: 9.5)
- ๐ CVE-2026-52805 (CVSS 3.1: 8.7)
- ๐ CVE-2026-52812 (CVSS 3.1: 8.0)
- ๐ CVE-2026-52810 (CVSS 3.1: 8.0)
๐ [HIGH] fossbilling/fossbilling
2 CVEs | CVSS 4.0: 10.0 | AAS 9.8
cpe:2.3:a:fossbilling:fossbilling:*:*:*:*:*:*:*:*
FOSSBilling, the open-source billing and client management platform, is affected by two vulnerabilities, including at least one critical-severity issue with a CVSS score of 10.0. The most severe flaw is an authorization bypass in API role handling that allows unauthenticated attackers to access privileged admin endpoints without valid credentials, sessions, or CSRF tokens, potentially granting full administrative control over the billing system. Organizations running FOSSBilling versions 0.5.4 through 0.7.x should upgrade to version 0.8.0 immediately, or as a temporary workaround block external access to the affected API paths at the web server level.
- ๐ CVE-2026-27604 (CVSS 4.0: 10.0)
- ๐ CVE-2026-28496 (CVSS 4.0: 9.4)
๐ [HIGH] flowise/flowise
1 CVE | CVSS 4.0: 8.7 | AAS 9.6
cpe:2.3:a:flowise:flowise:*:*:*:*:*:*:*:*
Flowise, the open-source AI workflow automation platform, is affected by a high-severity OS command injection vulnerability with a CVSS score of 8.7. The flaw exists in the Custom MCP Server feature, where incomplete command-flag validation and a regex bypass allow any authenticated user or API client to configure a malicious MCP server that executes arbitrary operating system commands on the host. Organizations running Flowise should upgrade to version 3.1.2 or later immediately, and review MCP server configurations for any signs of exploitation.
- ๐ CVE-2026-56274 (CVSS 4.0: 8.7)