VulnSea

flamingo vulnerabilities

CVEs whose affected-version data names the flamingo package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

3 CVEsRSS

CVE-2026-12853Medium· 5.4
2w ago

The Flamingo plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2

The Flamingo plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible …

Sunlitrocklobsterinc · FlamingoEPSS 0.31%via NVD
CVE-2026-61498Critical· 9.8
2mo ago

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters i…

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters i…

Midnightvitec · flamingoEPSS 4.1%via NVD
CVE-2026-60121Critical· 9.8PoC
2mo ago

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument …

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument …

Abyssalvitec · flamingoEPSS 2.3%via NVD
flamingo vulnerabilities (CVEs) · VulnSea