nginx-proxy-manager Prototype Pollution via JSON Parser Enables Unauthenticated RCE (CVE-2026-13228)
Scope: nginx-proxy-manager-2-rootfs Package Versions Prior to 2.13.1-r0
Severity: Red
Scope: Custom Payment Gateways for WooCommerce Plugin Versions up to and Including 2.1.0
Severity: High
Scope: Download Manager WordPress Plugin Versions up to and Including 3.3.60
Severity: Medium
Scope: NEX-Forms Ultimate Forms Plugin for WordPress Versions up to and Including 9.2.2
Severity: High
Scope: WSO2 API Manager, Versions 3.1.0, 3.2.0, 3.2.1, 4.0.0, and 4.2.0 Prior to Fixed Product Releases
Severity: High
Scope: Flowise, All Versions Lacking Registration Restrictions
Severity: Critical