PatchSiren

Mervin Praison CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Mervin Praison CVE published 2026-07-11

CVE-2026-60090

CVE-2026-60090 is a critical SQL injection vulnerability in PraisonAI before version 4.6.78. The vulnerability occurs in the PGVector and Cassandra knowledge-store create_collection() backends, where the dimension argument is not properly validated. This allows an attacker to inject malicious SQL/CQL tokens into the database driver. The vulnerability has a CVSS score of 9.3 and is considered critical. Aff [truncated]

MEDIUM Mervin Praison CVE published 2026-06-26

CVE-2026-57431

CVE-2026-57431 is a Medium-severity vulnerability in the Featured Image WordPress plugin, versions up to and including 2.1. The vulnerability, classified as Author Cross Site Scripting (XSS), has a CVSS score of 6.5. It was published on June 26, 2026, and last modified on June 29, 2026. The vulnerability allows an attacker to inject malicious scripts into the website, potentially leading to unauthorized a [truncated]