n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS) vulnerability in the Filter …
n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. When the node's Authentication p…
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which …
n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project…
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runner's prototype-freezing routine covers g…
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQL node. When a GraphQL request fails at…
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vulnerability in resource-locator field link preview…
n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation that allows authenticat…
n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an exp…
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the Form node's completion page. The completion page …
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update o…
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate operations, which …
n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP nod…
Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.
Unauthenticated Broken Access Control in Koji <= 2.2.1 versions.
Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
Subscriber Broken Authentication in Leyka <= 3.32.3 versions.