lubelog vulnerabilities
CVEs whose affected-version data names the lubelog package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-62279High· 7.1LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker
LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an authenticated user could submit caller-controlled recordIds to the DuplicateRecordsToOtherVehicles endpoint while naming…
▾ Twilighthargata · lubelogEPSS 0.36%via NVD
CVE-2026-62278High· 8.1LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker
LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authenticated non-administrative users could reach HandleTranslationFileUpload and influence the name passed from Controlle…
▾ Twilighthargata · lubelogEPSS 0.34%via NVD