CVE-2026-35643
High Severity
Description
OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untrusted pages ...
Related Vulnerabilities
- CVE-2026-3498: The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clien MEDIUM
- CVE-2026-35620: OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist MEDIUM
- CVE-2026-6035: A vulnerability has been found in code-projects Vehicle Showroom Management System 1.0. The affected MEDIUM
- CVE-2026-6036: A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. The impacted elem MEDIUM
- CVE-2026-34727: Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path HIGH
Related Coverage
Threat Actors