19 vulnerabilities across 15 products scored HIGH or above on July 13, 2026.

  • πŸ”΄ CRITICAL: 1
  • 🟠 HIGH: 18

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-57219 (rabbitmq/rabbitmq_server) β€” F1: theoretical β†’ itw, AAS: 10.9 β†’ 13.7 (HIGH β†’ CRITICAL). Originally in 2026-07-10 bulletin.
  • [UPGRADED] CVE-2026-55884 (tilt-dev/tilt) β€” F1: exploitable β†’ itw, AAS: 10.3 β†’ 13.0 (HIGH β†’ CRITICAL). Originally in 2026-07-10 bulletin.
  • [UPGRADED] CVE-2026-55879 (openreplay/openreplay) β€” F1: exploitable β†’ itw, AAS: 10.3 β†’ 13.3 (HIGH β†’ CRITICAL). Originally in 2026-07-10 bulletin.
  • [UPGRADED] CVE-2026-54003 (getkirby/kirby) β€” F1: theoretical β†’ poc, AAS: 11.8 β†’ 11.5 (HIGH β†’ HIGH). Originally in 2026-07-09 bulletin.
  • [UPGRADED] CVE-2026-59827 (metabase/metabase) β€” F1: exploitable β†’ itw, AAS: 11.2 β†’ 13.6 (HIGH β†’ CRITICAL). Originally in 2026-07-09 bulletin.
  • [UPGRADED] CVE-2026-59148 (mockoon/mockoon) β€” F1: exploitable β†’ itw, AAS: 9.6 β†’ 12.6 (HIGH β†’ CRITICAL). Originally in 2026-07-09 bulletin.
  • [UPGRADED] CVE-2026-59858 (vim/vim) β€” F1: exploitable β†’ itw, AAS: 9.3 β†’ 12.3 (HIGH β†’ CRITICAL). Originally in 2026-07-09 bulletin.
  • [UPGRADED] CVE-2026-55207 (pimcore/pimcore) β€” F1: theoretical β†’ poc, AAS: 9.1 β†’ 11.6 (HIGH β†’ HIGH). Originally in 2026-07-09 bulletin.
  • [UPGRADED] CVE-2026-57480 (parse-community/parse-server) β€” F1: theoretical β†’ poc, AAS: 9.8 β†’ 12.3 (HIGH β†’ CRITICAL). Originally in 2026-07-08 bulletin.
  • [UPGRADED] CVE-2026-59705 (mem0ai/mem0) β€” F1: exploitable β†’ itw, AAS: 10.7 β†’ 12.9 (HIGH β†’ CRITICAL). Originally in 2026-07-07 bulletin.
  • [UPGRADED] CVE-2026-53511 (kovidgoyal/calibre) β€” F1: exploitable β†’ itw, AAS: 9.4 β†’ 12.4 (HIGH β†’ CRITICAL). Originally in 2026-07-07 bulletin.

πŸ”΄ [CRITICAL] themeum/kirki

2 CVEs | CVSS 3.1: 9.8 | AAS 12.1

  • cpe:2.3:a:themeum:kirki:*:*:*:*:*:*:*:*

Themeum Kirki, a popular WordPress customizer framework plugin, is affected by 2 vulnerabilities including at least one critical-severity PHP object injection flaw (CVSS 9.8) caused by deserialization of untrusted data. All versions through 6.0.12 are confirmed vulnerable, and proof-of-concept exploit code is available, increasing the risk of near-term exploitation. WordPress administrators using the Kirki plugin should update beyond version 6.0.12 immediately or disable the plugin until a patch is applied, and review the vendor advisory at Patchstack for additional details.

Vendor Advisory


🟠 [HIGH] sergey/aiwu

1 CVE | CVSS 3.1: 9.3 | AAS 11.8

  • cpe:2.3:a:sergey:aiwu:*:*:*:*:*:*:*:*

AIWU (AI Copilot Content Generator), a WordPress plugin by Sergey, contains a blind SQL injection vulnerability (CVSS 9.3) affecting all versions through 1.5.4, with proof-of-concept exploit code publicly available. This flaw allows attackers to manipulate database queries, potentially leading to unauthorized data access or full site compromise. WordPress administrators running this plugin should update beyond version 1.5.4 immediately or deactivate it until a fix is available, and consult the Patchstack advisory for further guidance.

Vendor Advisory


🟠 [HIGH] latepoint/latepoint

1 CVE | CVSS 3.1: 9.3 | AAS 11.6

  • cpe:2.3:a:latepoint:latepoint:*:*:*:*:*:*:*:*

LatePoint, a WordPress appointment scheduling plugin, is affected by a blind SQL injection vulnerability (CVSS 9.3) in all versions through 5.6.3, with proof-of-concept exploit code already available. Successful exploitation could allow an attacker to extract sensitive data from the database, which is particularly concerning given that booking plugins typically store customer names, contact details, and payment information. Site administrators using LatePoint should update beyond version 5.6.3 immediately or disable the plugin, and review the Patchstack advisory for additional remediation guidance.

Vendor Advisory


🟠 [HIGH] wpwax/directorist

1 CVE | CVSS 3.1: 9.8 | AAS 11.6

  • cpe:2.3:a:wpwax:directorist:*:*:*:*:*:*:*:*

Directorist, a WordPress business directory and listing plugin by wpWax, contains a PHP object injection vulnerability (CVSS 9.8) caused by deserialization of untrusted data, affecting all versions through 8.8.2. Proof-of-concept exploit code is publicly available, and successful exploitation could allow an attacker to execute arbitrary code or fully compromise the site, particularly if a suitable gadget chain is present. WordPress administrators running Directorist should update beyond version 8.8.2 immediately or deactivate the plugin, and refer to the Patchstack advisory for further details.

Vendor Advisory


🟠 [HIGH] properfraction/mailoptin

1 CVE | CVSS 3.1: 9.8 | AAS 11.6

  • cpe:2.3:a:properfraction:mailoptin:*:*:*:*:*:*:*:*

MailOptin, a WordPress email opt-in and newsletter plugin by PropperFraction, contains a privilege escalation vulnerability (CVSS 9.8) caused by incorrect privilege assignment, affecting all versions through 1.2.77.3. Proof-of-concept exploit code is publicly available, and successful exploitation could allow a low-privileged or unauthenticated attacker to elevate to administrator, resulting in full site takeover. WordPress administrators using MailOptin should update beyond version 1.2.77.3 immediately or deactivate the plugin, and consult the Patchstack advisory for remediation details.

Vendor Advisory


🟠 [HIGH] melograno_venture_studio/amelia

1 CVE | CVSS 3.1: 9.3 | AAS 11.1

  • cpe:2.3:a:melograno_venture_studio:amelia:*:*:*:*:*:*:*:*

Amelia, a popular WordPress appointment and event booking plugin by Melograno Venture Studio, contains a blind SQL injection vulnerability (CVSS 9.3) affecting all versions through 2.4.2, with proof-of-concept exploit code publicly available. Given that Amelia is widely deployed and its database typically holds customer personal information, payment details, and booking records, exploitation poses a significant data breach risk. WordPress administrators running Amelia should update beyond version 2.4.2 immediately or deactivate the plugin, and review the Patchstack advisory for additional remediation guidance.

Vendor Advisory


🟠 [HIGH] diracgrid/dirac

2 CVEs | CVSS 3.1: 9.9 | AAS 10.7

  • cpe:2.3:a:diracgrid:dirac:*:*:*:*:*:*:*:* (< 9.0.0a24)

DIRAC, an open-source framework by DIRACGrid used for distributed computing in scientific and research environments, is affected by 2 vulnerabilities including at least one critical-severity remote code execution flaw (CVSS 9.9) that allows any authenticated user to execute arbitrary code on the DIRAC server via unsafe use of eval on untrusted input in the RequestManager component. Proof-of-concept exploit code is available for these issues, making exploitation straightforward for any user with valid credentials. Organizations running DIRAC infrastructure should apply patches immediately by consulting the GitHub security advisory, and audit server logs for signs of unauthorized command execution.

Vendor Advisory


🟠 [HIGH] marcus_(aka_@msykes)/events_manager

1 CVE | CVSS 3.1: 8.8 | AAS 10.6

  • cpe:2.3:a:marcus_aka_msykes:events_manager:*:*:*:*:*:*:*:*

Events Manager, a widely used WordPress plugin for managing events, bookings, and calendars, contains a PHP object injection vulnerability (CVSS 8.8) caused by deserialization of untrusted data, affecting all versions through 7.3.6. Proof-of-concept exploit code is publicly available, and exploitation could allow an attacker to inject malicious objects, potentially leading to remote code execution or full site compromise if a suitable gadget chain exists. WordPress administrators using Events Manager should update beyond version 7.3.6 immediately or deactivate the plugin, and refer to the Patchstack advisory for further remediation guidance.

Vendor Advisory


🟠 [HIGH] neorazorx/facturascripts

1 CVE | CVSS 3.1: 9.5 | AAS 10.6

  • cpe:2.3:a:neorazorx:facturascripts:*:*:*:*:*:*:*:*

FacturaScripts, an open-source ERP and invoicing platform by NeoRazorX, contains an authentication bypass vulnerability (CVSS 9.5) in its two-factor authentication login handler that allows an unauthenticated attacker to obtain a full session by brute-forcing TOTP codes without supplying a password or CSRF token. This vulnerability is considered actively exploitable, making it an immediate risk for any internet-facing FacturaScripts deployment, particularly given the sensitive financial and business data these systems typically hold. Administrators should patch immediately by consulting the GitHub security advisory, restrict public access to the login endpoint where possible, and review authentication logs for signs of brute-force activity against the two-factor validation endpoint.

Vendor Advisory


🟠 [HIGH] decolua/9router

3 CVEs | CVSS 4.0: 9.3 | AAS 9.9

  • cpe:2.3:a:decolua:9router:*:*:*:*:*:*:*:*

9Router, an AI provider routing tool by Decolua, is affected by 3 vulnerabilities including at least one critical-severity unauthenticated access flaw (CVSS 9.3) caused by missing authentication middleware on Next.js API routes, allowing remote attackers to enumerate, create, modify, or delete provider connections without credentials. Exploitation is considered straightforward and could expose OAuth tokens, API keys, and partial credentials, or allow attackers to redirect AI traffic to malicious servers. All versions through 0.4.41 are affected, and administrators should update immediately, restrict network access to the management API, and audit provider configurations and stored credentials for signs of tampering by consulting the GitHub security advisory.

Vendor Advisory


🟠 [HIGH] decidim/decidim

1 CVE | CVSS 3.1: 8.5 | AAS 9.7

  • cpe:2.3:a:decidim:decidim:*:*:*:*:*:*:*:*

Decidim, an open-source participatory democracy platform, contains a cross-organization JWT trust boundary vulnerability (CVSS 8.5) that allows a user authenticated against one organization to replay their token against another organization’s API, gaining unauthorized access to admin-only participant personal data and mutation endpoints such as proposal answering. This flaw is considered actively exploitable and is especially concerning for multi-tenant Decidim deployments where multiple organizations share the same infrastructure, as it breaks the fundamental isolation between tenants. Administrators should patch immediately by consulting the GitHub security advisory, audit API access logs for cross-organization token use, and review whether any participant data or proposal answers may have been accessed or modified by unauthorized parties.

Vendor Advisory


🟠 [HIGH] crewai/crewai

1 CVE | CVSS 4.0: 8.3 | AAS 9.7

  • cpe:2.3:a:crewai:crewai:*:*:*:*:*:*:*:* (< 1.15.1)

CrewAI, a popular AI agent orchestration framework, contains a server-side request forgery vulnerability (CVSS 8.3) in versions before 1.15.1 where the URL validation function can be bypassed via redirect-based or DNS rebinding attacks, allowing attackers to reach internal services and cloud metadata endpoints. This flaw is considered actively exploitable and poses a significant risk in cloud-hosted environments where metadata endpoints can expose instance credentials and sensitive configuration data. Teams running CrewAI should update to version 1.15.1 or later immediately, review network-level controls around internal service access, and consult the vendor’s commit for patch details.

Vendor Advisory


🟠 [HIGH] rejetto/hfs

1 CVE | CVSS 4.0: 9.3 | AAS 9.7

  • cpe:2.3:a:rejetto:hfs:*:*:*:*:*:*:*:*

Rejetto HFS (HTTP File Server) versions 3.0.0 through 3.2.0 contain a critical session forgery vulnerability (CVSS 9.3) where the session-cookie signing key is derived from the non-cryptographic Math.random() generator, whose outputs are disclosed to unauthenticated clients during login, allowing a remote attacker to reconstruct the key and forge administrator session cookies for full administrative access and remote code execution. This flaw is considered actively exploitable with minimal attacker effort, and HFS instances are frequently internet-facing, making them high-value targets. Administrators should update to version 3.2.1 or later immediately, rotate any existing session secrets, and review access logs for suspicious authentication activity.

Vendor Advisory


🟠 [HIGH] kimai/kimai

1 CVE | CVSS 3.1: 9.5 | AAS 9.3

  • cpe:2.3:a:kimai:kimai:*:*:*:*:*:*:*:*

Kimai, an open-source time-tracking application, contains a critical account takeover vulnerability (CVSS 9.5) in its official Docker image, which ships with a publicly known default Symfony APP_SECRET value that the entrypoint does not override or validate, allowing an unauthenticated attacker to forge HMAC-signed cookies and login links to compromise any account including super_admin. Any Docker-deployed Kimai instance where APP_SECRET was not explicitly changed is affected, and while exploitation is currently theoretical, the attack is trivial given the secret is publicly documented. Administrators should immediately set a unique, cryptographically random APP_SECRET environment variable, restart the application, invalidate all existing sessions, and consult the GitHub security advisory for additional guidance.

Vendor Advisory


🟠 [HIGH] openwrt/luci-app-banip

1 CVE | CVSS 4.0: 8.7 | AAS 9.1

  • cpe:2.3:a:openwrt:luci-app-banip:*:*:*:*:*:*:*:*

luci-app-banip, the LuCI web interface component for the banIP firewall tool on OpenWrt routers, contains a log parsing vulnerability (CVSS 8.7) where the awk-based parser blindly extracts the first IPv4 address from log lines regardless of field position, allowing an unauthenticated remote attacker to inject arbitrary IP addresses via attacker-controlled fields such as login usernames. This effectively lets an attacker weaponize the ban mechanism to block legitimate users or administrators while evading blocking themselves, undermining the core security function of the tool. OpenWrt administrators using banIP should apply the patched commit from the LuCI repository immediately, review current ban lists for injected entries, and monitor for suspicious login attempts containing IP address patterns in username fields.

Vendor Advisory