Solutions needed

Vulnerabilities that need a fix

These are CVEs that engineers have asked to be solved, ranked by how many people want them fixed. If a vulnerability you depend on has no published fix, add your voice on its page — we prioritise the ones the community most needs, and can develop and verify a patch.

  1. 1request CVE-2026-18991 A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp-tools/cor… High · 7.3
  2. 1request CVE-2026-7640 The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the `customer-area-protected-content` shortc… Medium · 6.4
  3. 1request CVE-2026-15622 A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor_manager/app/api/v1/workspace.py of the… Medium · 5.3

Demand is aggregated from “Request a fix” on each CVE. Need one solved now? Talk to us about a scoped engagement →