Capgo
83 CVEs tracked since 2026. Since Jun 2026, none of them reached CISA KEV.
Capgo CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-06 | 61 | 0 |
| 2026-07 | 22 | 0 |
Products
The products that kept showing up in Capgo's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Capgo.
- CVE-2026-56336Capgo - Information Disclosure via Unauthenticated SSO check-domain Endpoint5.3
- CVE-2026-56313Capgo - Cross-Organization Account Disruption via SSO Prelink Endpoint8.1
- CVE-2026-56308Capgo - Insufficient Authentication in Email Change Endpoint7.3
- CVE-2026-56281Capgo - SQL Injection via Unvalidated limit Parameter in Admin Stats Endpoint3.8
- CVE-2026-56252Capgo - Scope Isolation Failure in Webhook Test Endpoint5.4
- CVE-2026-56241Capgo - RBAC Demotion Privilege Retention via Stale org_users.user_right8.3
- CVE-2026-56238Capgo - Unauthenticated Information Disclosure via PostgREST global_stats Endpoint7.5
- CVE-2026-56303Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC Function7.5
- CVE-2026-56240Capgo - Billing Authorization Bypass via Exhausted Usage Credits4.3
- CVE-2026-56335Capgo - Channel Configuration Mutation via Write-Scoped API Keys6.5
- CVE-2026-56329Capgo - Cross-Tenant Preview Namespace Collision via Non-Bijective Underscore Decoding6.4
- CVE-2026-56312Capgo - Account Creation Before CAPTCHA Validation in accept_invitation Endpoint6.5
- CVE-2026-56309Capgo - Plan Bypass via Unrestricted Attachment Upload Endpoint5.4
- CVE-2026-56305Capgo - Authentication Bypass in Password Change via Missing Current Password Validation8.3
- CVE-2026-56279Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint7.5
The record
- Peak rank
- #13 in Jun 2026
- Busiest month shown
- Jun 2026, 61 CVEs
- Months with a KEV entry
- 0 since Jun 2026
- Monthly snapshots
- 2 since 2026