7.2

CVSS3.1

CVE-2026-35476 - InvenTree Affected by Privilege Escalation via API

InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate their account to a staff level via a POST request against their user account endpoint. The write permissions on the API endpoint are improperly configured, allowing any user…

📅 Published: April 8, 2026, 7:26 p.m. 🔄 Last Modified: April 8, 2026, 7:26 p.m.

8.3

CVSS3.1

CVE-2026-35478 - InvenTree has Arbitrary API Token Creation

InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token attributed to any other user in the system — including administrators and superusers — by supplying the target's user ID in the user field of a POST /a…

📅 Published: April 8, 2026, 7:24 p.m. 🔄 Last Modified: April 8, 2026, 7:24 p.m.

5.5

CVSS3.1

CVE-2026-35477 - InvenTree has SSTI in PART_NAME_FORMAT bypasses CVE-2026-27629 fix via {% if part.pk %} sandbox esc…

InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to use jinja2.sandbox.SandboxedEnvironment. However, the actual renderer in part/helpers.py was not updated and still uses the non-sandboxed jinja2.Enviro…

📅 Published: April 8, 2026, 7:20 p.m. 🔄 Last Modified: April 8, 2026, 7:20 p.m.

7.5

CVSS3.1

CVE-2026-23869 - CPU‑Exhaustion Denial of Service in React Server Components

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered …

📅 Published: April 8, 2026, 7:11 p.m. 🔄 Last Modified: April 9, 2026, 8:27 a.m.

7.3

CVSS3.1

CVE-2026-35455 - immich has Stored XSS via OCR Text in 360° Panorama Viewer

immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360° panorama viewer allows any authenticated user to execute arbitrary JavaScript in the browser of any other user who views the malicious panorama with the OCR o…

📅 Published: April 8, 2026, 6:31 p.m. 🔄 Last Modified: April 10, 2026, 3:55 a.m.

7.7

CVSS3.1

CVE-2026-35446 - LORIS has a path traversal in FilesDownloadHandler

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 24.0.0 to before 27.0.3 and 28.0.1, an incorrect order of operations in the FilesDownloadHandler could result in an attacker escaping t…

📅 Published: April 8, 2026, 6:28 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

6.5

CVSS3.1

CVE-2026-35403 - LORIS has potential cross-site scripting in survey_accounts module

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 15.10 to before 27.0.3 and 28.0.1, there is a potential for a cross-site scripting attack in the survey_accounts module if a user provi…

📅 Published: April 8, 2026, 6:27 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

3.5

CVSS3.1

CVE-2026-35400 - LORIS incorrectly trusts user input in publication module

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 and 28.0.1, an endpoint in the publication module was incorrectly trusting the baseURL submitted by a user's PO…

📅 Published: April 8, 2026, 6:26 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

8.7

CVSS3.1

CVE-2026-35169 - LORIS has potential cross-site scripting in help_editor module

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From to before 27.0.3 and 28.0.1, the help_editor module of LORIS did not properly sanitize some user supplied variables which could result…

📅 Published: April 8, 2026, 6:24 p.m. 🔄 Last Modified: April 9, 2026, 2:21 p.m.

6.3

CVSS3.1

CVE-2026-35165 - LORIS has incorrect access checks in document_repository

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 21.0.0 to before 27.0.3 and 28.0.1, while the document_repository frontend was restricting file access, the backend endpoint was not co…

📅 Published: April 8, 2026, 6:23 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.
Total resulsts: 343825
Page 53 of 34,383
« previous page » next page
Filters