| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-34937 | PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution | MervinPraison | PraisonAI | High | 7.8 | 2026-04-03 22:50:49 | Deep Dive |
| CVE-2026-34936 | PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback | MervinPraison | PraisonAI | High | 7.7 | 2026-04-03 22:50:05 | Deep Dive |
| CVE-2026-34934 | PraisonAI: Second-Order SQL Injection in `get_all_user_threads` | MervinPraison | PraisonAI | Critical | 9.8 | 2026-04-03 22:49:13 | Deep Dive |
| CVE-2026-34935 | PraisonAI: OS Command Injection in MCPHandler.parse_mcp_command() | MervinPraison | PraisonAI | Critical | 9.8 | 2026-04-03 22:48:21 | Deep Dive |
| CVE-2025-12019 | Featured Image <= 2.1 - Authenticated (Admin+) Stored Cross-Site Scripting | mervinpraison | Featured Image | Medium | 4.4 | 2025-11-11 03:30:53 | Deep Dive |