10

CVSS3.1

CVE-2025-65091 - XWiki Full Calendar Macro vulnerable to SQL injection through Calendar.JSONService

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONService page (including guest users) can exploit a SQL injection vulnerability by accessing database info or starting a DoS attack. This issue has been pat…

πŸ“… Published: Jan. 10, 2026, 3:06 a.m. πŸ”„ Last Modified: Jan. 29, 2026, 5:27 p.m.

5.3

CVSS3.1

CVE-2025-65090 - XWiki Full Calendar Macro vulnerable to data leak through Calendar.JSONService

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONService page (including guest users) can exploit the data leak vulnerability by accessing database info, with the exception of passwords. This issue has b…

πŸ“… Published: Jan. 10, 2026, 3:05 a.m. πŸ”„ Last Modified: Jan. 29, 2026, 5:27 p.m.

5.1

CVSS4.0

CVE-2026-22597 - Ghost has SSRF via External Media Inliner

Ghost is a Node.js content management system. In versions 5.38.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost’s media inliner mechanism allows staff users in possession of a valid authentication token for the Ghost Admin API to exfiltrate data from internal systems via SSRF. T…

πŸ“… Published: Jan. 10, 2026, 2:57 a.m. πŸ”„ Last Modified: April 18, 2026, 7:15 a.m.

6.7

CVSS3.1

CVE-2026-22596 - Ghost has SQL Injection in Members Activity Feed

Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's /ghost/api/admin/members/events endpoint allows users with authentication credentials for the Admin API to execute arbitrary SQL. This issue has been patched in vers…

πŸ“… Published: Jan. 10, 2026, 2:57 a.m. πŸ”„ Last Modified: April 18, 2026, 7:15 a.m.

8.1

CVSS3.1

CVE-2026-22595 - Ghost has Staff Token permission bypass

Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of Staff Token authentication allowed certain endpoints to be accessed that were only intended to be accessible via Staff Session authentication. External …

πŸ“… Published: Jan. 10, 2026, 2:57 a.m. πŸ”„ Last Modified: April 18, 2026, 7:15 a.m.

8.1

CVSS3.1

CVE-2026-22594 - Ghost has Staff 2FA bypass

Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism allows staff users to skip email 2FA. This issue has been patched in versions 5.130.6 and 6.11.0.

πŸ“… Published: Jan. 10, 2026, 2:56 a.m. πŸ”„ Last Modified: April 18, 2026, 7:15 a.m.

6.5

CVSS3.1

CVE-2026-22030 - React Router has CSRF issue in Action/Server Action Request Processing

React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side route action handlers in Framework Mode, or when us…

πŸ“… Published: Jan. 10, 2026, 2:42 a.m. πŸ”„ Last Modified: April 18, 2026, 4:45 p.m.

8

CVSS3.1

CVE-2026-22029 - React Router vulnerable to XSS via Open Redirects

React Router is a router for React. In @remix-run/router version prior to 1.23.2. and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs…

πŸ“… Published: Jan. 10, 2026, 2:42 a.m. πŸ”„ Last Modified: April 18, 2026, 7:15 a.m.

8.2

CVSS3.1

CVE-2026-21884 - React Router SSR XSS in ScrollRestoration

React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arb…

πŸ“… Published: Jan. 10, 2026, 2:41 a.m. πŸ”„ Last Modified: April 18, 2026, 7:15 a.m.

9.1

CVSS3.1

CVE-2025-61686 - React Router has Path Traversal in File Session Storage

React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/node (or @remix-run/node/@remix-run/deno in Remix v2) with an …

πŸ“… Published: Jan. 10, 2026, 2:41 a.m. πŸ”„ Last Modified: March 3, 2026, 6:11 p.m.
Total resulsts: 348556
Page 2141 of 34,856
Β« previous page Β» next page
Filters