9.4

CVSS4.0

CVE-2026-27497 - n8n has Potential Remote Code Execution via Merge Node

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could leverage the Merge node's SQL query mode to execute arbitrary code and write arbitrary files on the n8n server. The issues havโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 10:16 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3 p.m.

9.4

CVSS4.0

CVE-2026-27495 - n8n has a Sandbox Escape in its JavaScript Task Runner

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could exploit a vulnerability in the JavaScript Task Runner sandbox to execute arbitrary code outside the sandbox boundary. On instaโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 10:10 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:45 a.m.

7.1

CVSS4.0

CVE-2026-27494 - n8n has Arbitrary File Read via Python Code Node Sandbox Escape

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could use the Python Code node to escape the sandbox. The sandbox did not sufficiently restrict access to certain built-in Python obโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 10:08 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3 p.m.

9.5

CVSS4.0

CVE-2026-27493 - n8n has Unauthenticated Expression Evaluation via Form Node

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability existed in n8n's Form nodes that could allow an unauthenticated attacker to inject and evaluate arbitrary n8n expressions by submitting crafted form dโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 10:05 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:45 a.m.

8.9

CVSS4.0

CVE-2026-27148 - Storybook Dev Server Vulnerable to WebSocket Hijacking

Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10, the WebSocket functionality in Storybook's dev server, used to create and update stories, is vulnerable to WebSocket hijacking. This vulnerability oโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 9:46 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:45 a.m.

7.2

CVSS3.1

CVE-2026-27819 - Vikunja has Path Traversal in CLI Restore

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the restoreConfig function in vikunja/pkg/modules/dump/restore.go of the go-vikunja/vikunja repository fails to sanitize file paths within the provided ZIP archive. A maliciously crafted ZIP can bypass the intenโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 9:40 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3 p.m.

7.3

CVSS3.1

CVE-2026-27616 - Vikunja Vulnerable to Stored Cross-Site Scripting (XSS) via Unsanitized SVG Attachment Upload Leadiโ€ฆ

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to upload SVG files as task attachments. SVG is an XML-based format that supports JavaScript execution through elements such as <script> tags or event handlers like onload. The appliโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 9:37 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:45 a.m.

9.1

CVSS3.1

CVE-2026-27575 - Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength requirements. Additionally, active sessions remain valid after a user changes their password. An attacโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 9:35 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3 p.m.

6.1

CVSS3.1

CVE-2026-27116 - Vikunja has Reflected HTML Injection via filter Parameter in Projects Module

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, a reflected HTML injection vulnerability exists in the Projects module where the `filter` URL parameter is rendered into the DOM without output encoding when the user clicks "Filter." While `<script>` and `<ifraโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 9:33 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:45 a.m.

8.1

CVSS3.1

CVE-2026-26985 - LORIS vulnerable to path traversal in electrophysiology_browser

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Starting in version 24.0.0 and prior to versions 26.0.5, 27.0.2, and 28.0.0, an authenticated user with the appropriate authorization can reโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 9:26 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:45 a.m.
Total resulsts: 349182
Page 1434 of 34,919
ยซ previous page ยป next page
Filters