VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

GHSA-mh25-x5hq-wrqpHigh· 7.5
1mo ago

league/commonmark: Denial of service via colliding heading slugs

league/commonmark: Denial of service via colliding heading slugs

▾ Twilightleague · league/commonmarkvia GHSA
GHSA-mj63-m3rc-8pprMedium· 5.3
1mo ago

league/commonmark: Denial of service via deeply nested XML output

league/commonmark: Denial of service via deeply nested XML output

▾ Sunlitleague · league/commonmarkvia GHSA
GHSA-265m-7826-wjqmHigh
1mo ago

Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass

Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass

▾ Twilightcraftcms · craftcms/cmsvia GHSA
CVE-2026-14793Medium· 4.3
1mo ago

Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets

Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets

▾ Sunlitcraftcms · craftcms/cmsEPSS 0.39%via GHSA
GHSA-f5wm-88jv-g5hxHigh
1mo ago

Craft CMS: Authenticated RCE through Twig sandbox escape

Craft CMS: Authenticated RCE through Twig sandbox escape

▾ Twilightcraftcms · craftcms/cmsvia GHSA
CVE-2026-71433Medium· 5.3
1mo ago

LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver

LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted hierarc…

▾ Sunlitlanggraph-checkpoint-postgres · langgraph-checkpoint-postgresEPSS 0.36%via NVD
CVE-2026-64664Medium· 4.3
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belo…

▾ Sunlitstatamic · statamic/cmsEPSS 0.34%via NVD
CVE-2026-64665High· 8.1
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in a…

▾ Twilightstatamic · statamic/cmsEPSS 0.54%via NVD
CVE-2026-64663Medium· 6.5
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets, on sites whose templa…

▾ Sunlitstatamic · statamic/cmsEPSS 0.40%via NVD
CVE-2026-64662Medium· 6.5
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and cust…

▾ Sunlitstatamic · statamic/cmsEPSS 0.41%via NVD
CVE-2026-71434Medium· 5.3
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upload restrictions that the Control Panel enforces, so an unauthenticated visitor could up…

▾ Sunlitstatamic · statamic/cmsEPSS 0.41%via NVD
CVE-2026-71435Medium· 6.1
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values without escaping, allowing an unauthenticated form submit…

▾ Sunlitstatamic · statamic/cmsEPSS 0.34%via NVD
CVE-2026-71436Medium· 7.5
1mo ago

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial of service in the setXAxisR…

▾ Sunlitmermaid · mermaidEPSS 0.58%via NVD
CVE-2026-71437Medium
1mo ago

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.5.0 until 11.16.1, Mermaid Architecture Diagrams are vulnerable to prototype pollution when a diagram defines a group…

▾ Sunlitmermaid · mermaidEPSS 0.50%via NVD
CVE-2026-50159Medium
1mo ago

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied …

▾ Sunlitmermaid · mermaidEPSS 0.60%via NVD
CVE-2026-71438Low
1mo ago

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid's configuration setters (mermaid.initialize, mermaidAPI.setConfig, and mermaidAPI.updateSiteConf…

▾ Sunlitmermaid · mermaidEPSS 0.35%via NVD
CVE-2026-71439Medium
1mo ago

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow arbitrary large values for the ticks parameter, which can cause high …

▾ Sunlitmermaid · mermaidEPSS 0.53%via NVD
CVE-2026-71326Low· 3.8
1mo ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key bui…

▾ Sunlittraefik · traefikEPSS 0.34%via NVD
CVE-2026-71327High· 8.1
1mo ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go bui…

▾ Twilighttraefik · traefikEPSS 0.48%via NVD
CVE-2026-54764Medium· 5.8
1mo ago

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.28%via GHSA
CVE-2026-71325Medium· 4.4⚖ disputed
1mo ago

Traefik is an open-source edge router that makes publishing services a fun and easy experience

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolv…

▾ Sunlittraefik · traefikEPSS 0.15%via NVD
CVE-2026-54765Medium
1mo ago

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

▾ Sunlittraefik · github.com/traefik/traefik/v3EPSS 0.35%via GHSA
CVE-2026-65600Critical· 9.1
1mo ago

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

▾ Midnighttraefik · github.com/traefik/traefik/v2EPSS 0.62%via GHSA
CVE-2026-54763High
1mo ago

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

▾ Twilighttraefik · github.com/traefik/traefik/v2EPSS 0.24%via GHSA
CVE-2026-71324Critical· 9.1
1mo ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a plain HTTP/2 or HTTP/3 CONNECT request and its body to an HTTP/1.1 upstream through a sh…

▾ Midnighttraefik · traefikEPSS 0.69%via NVD
CVE-2026-45378High· 7.5
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin UI embeds verification_attachment blobs through reusable signed Act…

▾ Twilightdecidim-verifications · decidim-verificationsEPSS 0.42%via NVD
CVE-2026-45414High· 8.5
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be …

▾ Twilightdecidim · decidimEPSS 0.45%via NVD
CVE-2026-45415Medium· 6.0
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce full administrator authorizatio…

▾ Sunlitdecidim-verifications · decidim-verificationsEPSS 0.43%via NVD
CVE-2026-45572Medium· 4.8
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, an administrator with landing-page editing privileges can store arbitrary HTML and JavaScript in an HTML con…

▾ Sunlitdecidim-core · decidim-coreEPSS 0.25%via NVD
CVE-2026-45573Medium· 6.4
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, when VAPID delivery is enabled, the notification subscription flow stores a client-supplied push endpoint wi…

▾ Sunlitdecidim-core · decidim-coreEPSS 0.26%via NVD
CVEs tagged “ghsa” — page 51 · VulnSea