CVE-2026-35643
High Severity
Description
OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untrusted pages ...
Related Vulnerabilities
- CVE-2026-35667: OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-27486 where the !stop chat command MEDIUM
- CVE-2026-35656: OpenClaw before 2026.3.22 contains an authentication bypass vulnerability in the X-Forwarded-For hea MEDIUM
- CVE-2026-33710: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are gene HIGH
- CVE-2026-32930: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Obj HIGH
- CVE-2026-40168: Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vu HIGH
Related Coverage
Threat Actors