[{"cve_id": "CVE-2026-101033", "known_exploited": false, "description": "KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operations. Authenticated attackers can enumerate category IDs from other households to read their category", "cvss_score": 4.3, "severity": "medium", "published_date": "2026-09-27T14:16:29", "source_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101033"}, {"cve_id": "CVE-2026-101032", "known_exploited": false, "description": "navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Attackers can inject shell metacharacters through crafted file names in suggestion command directories t", "cvss_score": 7.0, "severity": "high", "published_date": "2026-09-27T14:16:28", "source_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101032"}, {"cve_id": "CVE-2026-100869", "known_exploited": false, "description": "Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers to trigger refunds on completed orders. Attackers with order tokens can submit arbitrary payme", "cvss_score": 5.9, "severity": "medium", "published_date": "2026-09-27T13:16:38", "source_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-100869"}, {"cve_id": "CVE-2026-100871", "known_exploited": false, "description": "Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endpoints. Attackers can register a shop customer account us", "cvss_score": 8.8, "severity": "high", "published_date": "2026-09-27T13:16:38", "source_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-100871"}, {"cve_id": "CVE-2026-100870", "known_exploited": false, "description": "Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens t", "cvss_score": 8.8, "severity": "high", "published_date": "2026-09-27T13:16:38", "source_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-100870"}, {"cve_id": "CVE-2026-100872", "known_exploited": false, "description": "Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a smal", "cvss_score": 7.5, "severity": "high", "published_date": "2026-09-27T13:16:38", "source_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-100872"}, {"cve_id": "CVE-2026-100867", "known_exploited": false, "description": "spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before rendering them in the zsh prompt. Attackers can embed ANSI/OSC escape sequences in version fields of packag", "cvss_score": 3.3, "severity": "low", "published_date": "2026-09-27T13:16:37", "source_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-100867"}, {"cve_id": "CVE-2026-100868", "known_exploited": false, "description": "Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to ", "cvss_score": 6.3, "severity": "medium", "published_date": "2026-09-27T13:16:37", "source_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-100868"}, {"cve_id": "CVE-2026-100866", "known_exploited": false, "description": "onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in projec", "cvss_score": 3.3, "severity": "low", "published_date": "2026-09-27T13:16:36", "source_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-100866"}, {"cve_id": "CVE-2026-97165", "known_exploited": false, "description": "Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The \u201creturn\u201d parameter is base64-decoded and written to the \u201cBack\u201d link without being validated.", "cvss_score": 0.0, "severity": "medium", "published_date": "2026-09-27T12:17:12", "source_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-97165"}]