6.5

CVSS3.1

CVE-2026-33541 - TSPortal's Uncontrolled User Creation via Validation Side Effects Leads to Potential Denial of Serv…

TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparency work. Prior to version 34, a flaw in TSPortal allowed attackers to create arbitrary user records in the database by abusing validation logic. While …

πŸ“… Published: March 26, 2026, 8:27 p.m. πŸ”„ Last Modified: March 27, 2026, 8:01 p.m.

4.8

CVSS4.0

CVE-2026-33738 - Lychee Vulnerable to Stored XSS via Photo Description in RSS/Atom/JSON Feed (No Sanitization on Pub…

Lychee is a free, open-source photo-management tool. Prior to version 7.5.3, the photo `description` field is stored without HTML sanitization and rendered using `{!! $item->summary !!}` (Blade unescaped output) in the RSS, Atom, and JSON feed templates. The `/feed` endpoint is publicly accessible …

πŸ“… Published: March 26, 2026, 8:25 p.m. πŸ”„ Last Modified: March 27, 2026, 8:32 a.m.

0.0

CVE-2026-4393 - Automated Logout - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-030

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Automated Logout allows Cross Site Request Forgery.This issue affects Automated Logout: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.2.

πŸ“… Published: March 26, 2026, 8:10 p.m. πŸ”„ Last Modified: March 27, 2026, 8:32 a.m.

0.0

CVE-2026-4933 - Unpublished Node Permissions - Critical - Access bypass - SA-CONTRIB-2026-029

Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions allows Forceful Browsing.This issue affects Unpublished Node Permissions: from 0.0.0 before 1.7.0.

πŸ“… Published: March 26, 2026, 8:10 p.m. πŸ”„ Last Modified: March 27, 2026, 8:32 a.m.

0.0

CVE-2026-3573 - AI (Artificial Intelligence) - Moderately critical - Information Disclosure - SA-CONTRIB-2026-028

Incorrect Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Resource Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.1.11, from 1.2.0 before 1.2.12.

πŸ“… Published: March 26, 2026, 8:10 p.m. πŸ”„ Last Modified: March 27, 2026, 8:32 a.m.

5.4

CVSS3.1

CVE-2026-21724 - Missing Protected-field Authorization in Provisioning Contact Points API

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.

πŸ“… Published: March 26, 2026, 8:06 p.m. πŸ”„ Last Modified: March 29, 2026, 8:27 p.m.

6.5

CVSS3.1

CVE-2026-33375 - Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS

The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catastrophic Out-Of-Memory (OOM) memory exhaustion, crashing the host container.

πŸ“… Published: March 26, 2026, 8:05 p.m. πŸ”„ Last Modified: March 29, 2026, 8:27 p.m.

2.3

CVSS4.0

CVE-2026-33644 - Lychee has SSRF bypass via DNS rebinding β€” PhotoUrlRule only validates IP addresses, not hostnames …

Lychee is a free, open-source photo-management tool. Prior to version 7.5.2, the SSRF protection in `PhotoUrlRule.php` can be bypassed using DNS rebinding. The IP validation check (line 86-89) only activates when the hostname is an IP address. When a domain name is used, `filter_var($host, FILTER_V…

πŸ“… Published: March 26, 2026, 8:04 p.m. πŸ”„ Last Modified: March 27, 2026, 8:32 a.m.

4.2

CVSS3.1

CVE-2026-3532 - OpenID Connect / OAuth client - Less critical - Access bypass - SA-CONTRIB-2026-027

Improper Handling of Case Sensitivity vulnerability in Drupal OpenID Connect / OAuth client allows Privilege Escalation.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.

πŸ“… Published: March 26, 2026, 8:04 p.m. πŸ”„ Last Modified: March 27, 2026, 8:26 p.m.

0.0

CVE-2026-3531 - OpenID Connect / OAuth client - Moderately critical - Access bypass - SA-CONTRIB-2026-026

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Authentication Bypass.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.

πŸ“… Published: March 26, 2026, 8:03 p.m. πŸ”„ Last Modified: March 27, 2026, 8:32 a.m.
Total resulsts: 341069
Page 40 of 34,107
Β« previous page Β» next page
Filters