VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-70609Medium· 5.7
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the…

▾ Sunlitelectron · electronEPSS 0.55%via NVD
CVE-2026-70610Medium· 5.4
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could car…

▾ Sunlitelectron · electronEPSS 0.58%via NVD
CVE-2026-70611Medium· 6.9
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in file manager action could launch the target file rather th…

▾ Sunlitelectron · electronEPSS 0.18%via NVD
CVE-2026-70603Medium· 6.0
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject paths containing embedded null bytes. Apps that p…

▾ Sunlitelectron · electronEPSS 0.14%via NVD
CVE-2026-70602Medium· 6.6
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting APIs were not scoped to the extension's own session. …

▾ Sunlitelectron · electronEPSS 0.26%via NVD
CVE-2026-70604High· 7.4
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0, a custom scheme registered with supportFetchAPI: true but without corsEnabled: true was…

▾ Twilightelectron · electronEPSS 0.35%via NVD
CVE-2026-70605Medium· 5.9
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, net.fetch() and net.request() did not restrict whi…

▾ Sunlitelectron · electronEPSS 0.32%via NVD
CVE-2026-70606Medium· 5.9
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0, when a custom protocol handler returned a ProtocolResponse with a url and no session, E…

▾ Sunlitelectron · electronEPSS 0.26%via NVD
CVE-2026-70607Medium· 5.3
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, some window options supplied by web content in the window.open() features string …

▾ Sunlitelectron · electronEPSS 0.58%via NVD
CVE-2026-70597Medium· 6.3
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the check Electron uses on macOS to confirm it was launched by a same-signed pare…

▾ Sunlitelectron · electronEPSS 0.11%via NVD
CVE-2026-70598Low· 3.9
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data received from the GPU process was not fully valid…

▾ Sunlitelectron · electronEPSS 0.14%via NVD
CVE-2026-70599Medium· 5.9
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level …

▾ Sunlitelectron · electronEPSS 0.19%via NVD
CVE-2026-70600Low· 3.1
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup could be positioned by a cross-origin iframe outside th…

▾ Sunlitelectron · electronEPSS 0.22%via NVD
CVE-2026-70601High· 7.5
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may…

▾ Twilightelectron · electronEPSS 0.30%via NVD
CVE-2026-70595Medium· 4.0
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost serve…

▾ Sunlitghost · ghostEPSS 0.28%via NVD
CVE-2026-70596Medium· 4.3
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin …

▾ Sunlitghost · ghostEPSS 0.32%via NVD
CVE-2026-53949Medium· 5.3
1mo ago

Ghost Content API filter bypass reveals private fields

Ghost Content API filter bypass reveals private fields

▾ Sunlitghost · ghostEPSS 0.36%via GHSA
CVE-2026-70593Medium· 6.6
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation t…

▾ Sunlitghost · ghostEPSS 0.41%via NVD
CVE-2026-70594Medium· 6.7
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another v…

▾ Sunlitghost · ghostEPSS 0.24%via NVD
CVE-2026-53950High· 7.5
1mo ago

XSS in Ghost's ActivityPub client

XSS in Ghost's ActivityPub client

▾ Twilighttryghost · @tryghost/activitypubEPSS 0.35%via GHSA
CVE-2026-53947Medium· 5.3
1mo ago

Ghost: Member existence leak via magic link sign-in response

Ghost: Member existence leak via magic link sign-in response

▾ Sunlitghost · ghostEPSS 0.34%via GHSA
CVE-2026-59817Medium· 5.3
1mo ago

Ghost: Paid gift memberships obtainable at minimal cost via the donations feature

Ghost: Paid gift memberships obtainable at minimal cost via the donations feature

▾ Sunlitghost · ghostEPSS 0.40%via GHSA
CVE-2026-70489Medium· 6.5
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automations.py anchored minutely and hourly rules at a fixed date of…

▾ Sunlitopenwebui · open_webuiEPSS 0.57%via NVD
CVE-2026-70490Medium· 6.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/terminals.py authenticated its own first-message JWT and never appl…

▾ Sunlitopenwebui · open_webuiEPSS 0.28%via NVD
CVE-2026-70491Medium· 6.5
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in backend/open_webui/routers/tools.py r…

▾ Sunlitopenwebui · open_webuiEPSS 0.48%via NVD
CVE-2026-70492High· 8.7
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a chat message whose math block makes K…

▾ Twilightopenwebui · open_webuiEPSS 0.40%via NVD
CVE-2026-70493Medium· 6.5
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let a c…

▾ Sunlitopenwebui · open_webuiEPSS 0.59%via NVD
CVE-2026-70494High· 8.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a sha…

▾ Twilightopenwebui · open_webuiEPSS 0.55%via NVD
CVE-2026-70588Medium· 5.0
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.

▾ Sunlitghost · ghostEPSS 0.43%via NVD
CVE-2026-53948Medium· 5.4
1mo ago

Ghost: File Upload Content-Type Spoofing

Ghost: File Upload Content-Type Spoofing

▾ Sunlitghost · ghostEPSS 0.23%via GHSA
CVEs tagged “ghsa” — page 53 · VulnSea