VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3812 CVEsRSS

CVE-2026-12259Medium· 5.3
2w ago

NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection

NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection

▾ Sunlitnltk · nltkEPSS 0.14%via OSV
CVE-2026-76969Critical· 9.4
2w ago

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive …

▾ MidnightSAP_SE · SAP Cloud Application Programming Model (CAP)EPSS 0.44%via NVD
CVE-2026-78675High· 8.4⚖ disputed
2w ago

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables…

GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

▾ Twilightgitpython · gitpythonEPSS 0.18%via OSV
CVE-2026-80206High
2w ago

NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions

▾ Twilightnltk · nltkEPSS 0.44%via OSV
CVE-2026-78681High
2w ago

NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

▾ Twilightnltk · nltkEPSS 0.52%via OSV
CVE-2026-79676High
2w ago

NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

▾ Twilightnltk · nltkEPSS 0.45%via OSV
CVE-2026-79657Critical
2w ago

NLTK: Allowlisted pickle loaders still permit code execution in current source

NLTK: Allowlisted pickle loaders still permit code execution in current source

▾ Midnightnltk · nltkEPSS 1.3%via OSV
CVE-2026-78683Critical
2w ago

NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution

NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution

▾ Midnightnltk · nltkEPSS 0.51%via OSV
CVE-2026-53637Medium· 6.5
2w ago

Sylius is an Open Source eCommerce Framework on Symfony

Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is co…

▾ SunlitSylius · SyliusEPSS 0.36%via NVD
CVE-2026-53638Medium· 4.3
2w ago

Sylius is an Open Source eCommerce Framework on Symfony

Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an authorization bypass vulnerability exists in the shop account API. The `PATCH /api/v2/shop/account/orde…

▾ SunlitSylius · SyliusEPSS 0.28%via NVD
CVE-2026-53639Medium· 6.3
2w ago

Sylius is an Open Source eCommerce Framework on Symfony

Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop/payment-requests/{hash}` endpoints lo…

▾ SunlitSylius · SyliusEPSS 0.54%via NVD
CVE-2026-86439High· 8.8
3w ago

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory…

▾ Twilightknowns-dev · knownsEPSS 1.1%via NVD
CVE-2026-52762High· 7.1PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic template feature that can be escalated to confirmed Remote Code Executio…

▾ MidnightYesWiki · yeswikiEPSS 0.78%via NVD
CVE-2026-52763Medium· 6.5
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts a period argument from two disjoint parameter spaces. A whitelist validates only the URL form against ['day','w…

▾ SunlitYesWiki · yeswikiEPSS 0.38%via NVD
CVE-2026-52766Critical· 9.1PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that arra…

▾ AbyssalYesWiki · yeswikiEPSS 0.58%via NVD
CVE-2026-52767High· 8.2PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify(...)) { throw ..…

▾ MidnightYesWiki · yeswikiEPSS 0.35%via NVD
CVE-2026-52769High· 8.3PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:"public" - accepts an HTTP Signature header whose keyId parameter is a URL. H…

▾ MidnightYesWiki · yeswikiEPSS 0.49%via NVD
CVE-2026-52770High· 7.5PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric query / queries filters. For Bazar fields whose value structure is nume…

▾ MidnightYesWiki · yeswikiEPSS 0.47%via NVD
CVE-2026-52771High· 8.3
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into a DELETE FROM …_links WHERE to_tag = '$tag' query without escaping.…

▾ TwilightYesWiki · yeswikiEPSS 0.51%via NVD
CVE-2026-52772Medium· 5.5PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body contexts, resulting stored XSS in form renders. This issue has b…

▾ TwilightYesWiki · yeswikiEPSS 0.34%via NVD
CVE-2026-52773Medium· 6.1PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. Because MySQL coer…

▾ TwilightYesWiki · yeswikiEPSS 0.59%via NVD
CVE-2026-52774Medium· 6.1PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter into HTML attributes using strip_tags() only. Because strip_tags() does not escape double quotes, an attacker c…

▾ TwilightYesWiki · yeswikiEPSS 0.66%via NVD
CVE-2026-52775High· 8.8PoC
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject a…

▾ MidnightYesWiki · yeswikiEPSS 0.48%via NVD
CVE-2026-52777Critical· 9.4
3w ago

YesWiki is a wiki system written in PHP

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6.

▾ MidnightYesWiki · yeswikiEPSS 0.28%via NVD
GHSA-7q9c-hpx7-9cwmHigh· 7.5
3w ago

TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop

TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop

▾ Twilighttypespec · @typespec/spectorvia GHSA
CVE-2026-63733Medium· 4.3
3w ago

SurrealDB: Writes in a PERMISSIONS clause bypass table permissions

SurrealDB: Writes in a PERMISSIONS clause bypass table permissions

▾ Sunlitsurrealdb-core · surrealdb-coreEPSS 0.29%via GHSA
CVE-2026-72799Medium· 5.8
3w ago

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers

SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via OSV
CVE-2026-72798High· 8.6
3w ago

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns

SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.43%via GHSA
CVE-2026-72796Medium· 5.8
3w ago

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers

SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.35%via GHSA
CVE-2026-72794High· 8.6
3w ago

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.42%via OSV
CVEs tagged “ghsa” — page 21 · VulnSea