8.2

CVSS4.0

CVE-2026-35525 - LiquidJS has a root restriction bypass for partial and layout loading through symlinked templates

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, for {% include %}, {% render %}, and {% layout %}, LiquidJS checks whether the candidate path is inside the configured partials or layouts roots before reading it. That check is path-based, not reaโ€ฆ

๐Ÿ“… Published: April 8, 2026, 7:30 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 9:19 p.m.

6.6

CVSS3.1

CVE-2026-35479 - InvenTree Plugin Installation - Insufficient Permissions

InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permissions can install plugins via the API, without requiring "superuser" account access. This level of permission requirement is out of alignment with other plugin actions (such as uโ€ฆ

๐Ÿ“… Published: April 8, 2026, 7:27 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 2:16 p.m.

7.2

CVSS3.1

CVE-2026-35476 - InvenTree Affected by Privilege Escalation via API

InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can elevate their account to a staff level via a POST request against their user account endpoint. The write permissions on the API endpoint are improperly configured, allowing any userโ€ฆ

๐Ÿ“… Published: April 8, 2026, 7:26 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:26 p.m.

8.3

CVSS3.1

CVE-2026-35478 - InvenTree has Arbitrary API Token Creation

InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user can create a valid API token attributed to any other user in the system โ€” including administrators and superusers โ€” by supplying the target's user ID in the user field of a POST /aโ€ฆ

๐Ÿ“… Published: April 8, 2026, 7:24 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:24 p.m.

5.5

CVSS3.1

CVE-2026-35477 - InvenTree has SSTI in PART_NAME_FORMAT bypasses CVE-2026-27629 fix via {% if part.pk %} sandbox escโ€ฆ

InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to use jinja2.sandbox.SandboxedEnvironment. However, the actual renderer in part/helpers.py was not updated and still uses the non-sandboxed jinja2.Enviroโ€ฆ

๐Ÿ“… Published: April 8, 2026, 7:20 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 8:43 p.m.

7.5

CVSS3.1

CVE-2026-23869 - CPUโ€‘Exhaustion Denial of Service in React Server Components

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered โ€ฆ

๐Ÿ“… Published: April 8, 2026, 7:11 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 8:27 a.m.

7.3

CVSS3.1

CVE-2026-35455 - immich has Stored XSS via OCR Text in 360ยฐ Panorama Viewer

immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360ยฐ panorama viewer allows any authenticated user to execute arbitrary JavaScript in the browser of any other user who views the malicious panorama with the OCR oโ€ฆ

๐Ÿ“… Published: April 8, 2026, 6:31 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 3:55 a.m.

7.7

CVSS3.1

CVE-2026-35446 - LORIS has a path traversal in FilesDownloadHandler

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 24.0.0 to before 27.0.3 and 28.0.1, an incorrect order of operations in the FilesDownloadHandler could result in an attacker escaping tโ€ฆ

๐Ÿ“… Published: April 8, 2026, 6:28 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:25 p.m.

6.5

CVSS3.1

CVE-2026-35403 - LORIS has potential cross-site scripting in survey_accounts module

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 15.10 to before 27.0.3 and 28.0.1, there is a potential for a cross-site scripting attack in the survey_accounts module if a user proviโ€ฆ

๐Ÿ“… Published: April 8, 2026, 6:27 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 8:42 p.m.

3.5

CVSS3.1

CVE-2026-35400 - LORIS incorrectly trusts user input in publication module

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 and 28.0.1, an endpoint in the publication module was incorrectly trusting the baseURL submitted by a user's POโ€ฆ

๐Ÿ“… Published: April 8, 2026, 6:26 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:25 p.m.
Total resulsts: 343887
Page 59 of 34,389
ยซ previous page ยป next page
Filters