CVE-2026-35670
Medium Severity
Description
OpenClaw before 2026.3.22 contains a webhook reply delivery vulnerability that allows attackers to rebind chat replies to unintended users by exploiting mutabl...
Related Vulnerabilities
- CVE-2026-40260: pypdf: Manipulated XMP metadata entity declarations can exhaust RAM MEDIUM
- CVE-2026-34480: Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , i MEDIUM
- CVE-2026-33707: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password r CRITICAL
- CVE-2026-33141: Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Referenc MEDIUM
- CVE-2026-2305: The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via MEDIUM
Related Coverage
Threat Actors