CWE-235
CVEs classified under CWE-235, newest first.
2 CVEsRSS
GHSA-92hr-gmr6-h8cpMediumEtherpad addressed weak token RNG, login timing, plugin path handling, API request handling
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
▾ Sunlitep_etherpad-lite · ep_etherpad-litevia GHSA
CVE-2026-27851High· 7.4When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authent…
▾ Twilightdovecot · dovecotEPSS 0.41%via NVD