Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Capgo — Vulnerabilities & Security Advisories 83

Browse all 83 CVE security advisories affecting Capgo. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerabilities associated with the Capgo vendor, focusing on weaknesses classified under the Common Weakness Enumeration (CWE) standard. It compiles a comprehensive list of known security issues, tracking data from early reports through the most recent advisories published by the vendor. The content covers various risk levels and software components, ensuring a holistic view of the security posture. Users can utilize this resource to track a vendor's advisories over time, observing how quickly issues are acknowledged and resolved. The page allows security professionals and developers to understand a specific weakness class as it applies to Capgo’s ecosystem, identifying patterns in recurring flaws or specific architectural risks. Additionally, individuals can look up a product's vulnerability history to assess the long-term stability and maintenance quality of the software. By centralizing this information, the page serves as a critical reference for risk assessment, helping stakeholders make informed decisions about software procurement, patching priorities, and compatibility checks. This structured approach eliminates the need to scour multiple sources for disjointed data, providing a single point of truth for Capgo-related security concerns.

Found 82 results / 83 Clear Filters
Top products by Capgo: Capgo cli
CVE ID Title CVSS Severity Published
CVE-2026-56253 Capgo - Unauthenticated Organization Member Email Disclosure via get_org_members RPC — Capgo CWE-284 7.5 High 2026-06-21
CVE-2026-56251 Capgo - Privilege Escalation via Broken Row Level Security in org_users — Capgo CWE-266 6.5 Medium 2026-06-21
CVE-2026-56242 Capgo - Unauthenticated API Key Validity Oracle and User Identity Disclosure via get_identity_apikey_only RPC — Capgo CWE-200 7.5 High 2026-06-21
CVE-2026-56239 Capgo - Privilege Escalation via SECURITY DEFINER Function apply_usage_overage — Capgo CWE-269 7.6 High 2026-06-21
CVE-2026-56229 Capgo - Cross-App Build Job Access via app_id/job_id Mismatch in /build/status and /build/logs — Capgo CWE-639 6.5 Medium 2026-06-21
CVE-2026-56332 Capgo - Open Redirect via confirmation_url Parameter — Capgo CWE-601 4.7 Medium 2026-06-20
CVE-2026-56330 Capgo - Open Redirect via Unvalidated Stripe Billing URLs — Capgo CWE-601 3.5 Low 2026-06-20
CVE-2026-56319 Capgo - App Existence Oracle via GET /statistics/app/:app_id — Capgo CWE-203 4.3 Medium 2026-06-20
CVE-2026-56295 Capgo - Policy Enforcement Bypass in Webhook Management Endpoints via Non-Expiring API Keys — Capgo CWE-285 6.3 Medium 2026-06-20
CVE-2026-56282 Capgo - Information Disclosure via Unauthenticated /replication Endpoint — Capgo CWE-200 5.3 Medium 2026-06-20
CVE-2026-56228 Capgo - Denial of Service via Improper Password Policy Length Validation — Capgo CWE-20 4.9 Medium 2026-06-20
CVE-2026-56218 Capgo - EXIF Metadata Exposure via Image Upload — Capgo CWE-200 5.3 Medium 2026-06-20
CVE-2026-56227 Capgo - Server-Side Request Forgery via Webhook URL Validation — Capgo CWE-918 5.4 Medium 2026-06-20
CVE-2026-56325 Capgo - App ID Confusion via ILIKE Wildcard in Preview Subdomain Lookup — Capgo CWE-20 3.1 Low 2026-06-20
CVE-2026-56216 Capgo - Scope Escalation via API Key Creation in /functions/v1/apikey — Capgo CWE-269 8.8 High 2026-06-20
CVE-2026-56214 Capgo - Unauthenticated Organization Enumeration and Billing Status Disclosure via Supabase RPC — Capgo CWE-200 7.5 High 2026-06-20
CVE-2026-56215 Capgo - Account Merge via Poisoned public.users.email in SSO Provisioning — Capgo CWE-639 8.3 High 2026-06-20
CVE-2026-56213 Capgo - Unauthenticated Cross-Tenant Metrics Poisoning via upsert_version_meta RPC — Capgo CWE-862 5.3 Medium 2026-06-20
CVE-2026-56212 Capgo - Improper 2FA Enforcement Logic via Team Security Settings — Capgo CWE-269 3.8 Low 2026-06-20
CVE-2026-56079 Capgo - Cross-Tenant Authorization Bypass via PostgREST Webhook Access — Capgo CWE-200 6.5 Medium 2026-06-19
CVE-2026-53867 Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement — Capgo CWE-459 4.3 Medium 2026-06-12
CVE-2026-53868 Capgo < 12.128.2 - Denial of Service via Unverified Email Account Registration and Deletion — Capgo CWE-306 7.5 High 2026-06-12

This page lists every published CVE security advisory associated with Capgo. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.