| CVE-2026-73646 | |
| GHSA-55q2-fjhq-7xh7 | |
| GHSA-38gx-cfqf-f652 | |
| Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | |
| Information Exposure | |
| GHSA-32rq-jhr7-m3hh | |
| Information Exposure | |
| GHSA-mjrx-74jh-7xgw | |
| Directory Traversal | |
| GHSA-mqq9-gxg5-m58g | |
| Allocation of Resources Without Limits or Throttling | |
| Information Exposure | |
| GHSA-fxqj-rqcc-2cmp | |
| GHSA-3fvr-2jw6-crq4 | |
| GHSA-mh99-v99m-4gvg | |
| GHSA-r28c-9q8g-f849 | |
| CVE-2026-14257 | |
| GHSA-c2j3-45gr-mqc4 | |
| Cross-site Scripting (XSS) | |
| Protection Mechanism Failure | |
| Cross-site Scripting (XSS) | |
| Cross-site Scripting (XSS) | |
| Trust Boundary Violation | |
| GHSA-mmx7-hfxf-jppx | |
| GHSA-wm3w-8rrp-j577 | |
| CVE-2026-13149 | |
| GHSA-3jxr-9vmj-r5cp | |
| GHSA-jqh4-m9w3-8hp9 | |
| GHSA-f4gw-2p7v-4548 | |
| GHSA-gcfj-64vw-6mp9 | |
| GHSA-hcpx-6fm6-wx23 | |
| GHSA-mwf2-3pr3-8698 | |
| GHSA-xj6q-8x83-jv6g | |
| GHSA-h95v-h523-3mw8 | |
| GHSA-42h9-826w-cgv3 | |
| GHSA-pmv8-rq9r-6j72 | |
| GHSA-94pj-82f3-465w | |
| GHSA-7q8q-rj6j-mhjq | |
| GHSA-f283-ghqc-fg79 | |
| Server-Side Request Forgery (SSRF) | |
| GHSA-rf66-hmqf-q3fc | |
| Cross-site Scripting (XSS) | |
| GHSA-vxr8-fq34-vvx9 | |
| GHSA-cmwh-pvxp-8882 | |
| Uncontrolled Recursion | |
| GHSA-48c2-rrv3-qjmp | |
| CVE-2026-12143 | |
| GHSA-hmw2-7cc7-3qxx | |
| Arbitrary Code Injection | |
| GHSA-3mfm-83xf-c92r | |
| GHSA-xjpj-3mr7-gcpf | |
| Cross-site Scripting (XSS) | |
| GHSA-9cx6-37pm-9jff | |
| GHSA-2w6w-674q-4c4q | |
| GHSA-2qvq-rjwj-gvw9 | |
| Arbitrary Code Injection | |
| GHSA-xhpv-hc6g-r9c6 | |
| Arbitrary Code Injection | |
| Improper Check for Unusual or Exceptional Conditions | |
| GHSA-442j-39wm-28r2 | |
| Cross-site Scripting (XSS) | |
| GHSA-7rx3-28cr-v5wh | |
| GHSA-cwxw-98qj-8qjx | |
| GHSA-38cx-cq6f-5755 | |
| GHSA-x4vx-rjvf-j5p4 | |
| Cross-site Scripting (XSS) | |
| Origin Validation Error | |
| GHSA-76mc-f452-cxcm | |
| GHSA-gvmj-g25r-r7wr | |
| GHSA-vm85-hxw5-5432 | |
| Cross-site Scripting (XSS) | |
| CRLF Injection | |
| Cross-site Scripting (XSS) | |
| Missing Encryption of Sensitive Data | |
| Incomplete Blacklist | |
| GHSA-wpwq-4j6v-78m3 | |
| GHSA-r47g-fvhr-h676 | |
| GHSA-m557-wrgg-6rp4 | |
| GHSA-hpcv-96wg-7vj8 | |
| GHSA-rp9w-3fw7-7cwq | |
| GHSA-x6g4-fwcc-jj8w | |
| Incorrect Regular Expression | |
| CRLF Injection | |
| GHSA-2xf4-cg6j-vhgq | |
| Arbitrary Argument Injection | |
| GHSA-xx3c-qf5g-hc39 | |
| CRLF Injection | |
| GHSA-72xp-p242-47p9 | |
| XML External Entity (XXE) Injection | |
| GHSA-vqc8-7275-q272 | |
| GHSA-qpmx-3rfj-7rhv | |
| Improper Validation of Unsafe Equivalence in Input | |
| Information Exposure | |
| GHSA-94g3-g5v7-q4jg | |
| Information Exposure | |
| GHSA-27qh-8cxx-2cr5 | |
| GHSA-r854-jrxh-36qx | |
| GHSA-f7pm-6hr8-7ggm | |
| Origin Validation Error | |
| GHSA-3rg7-wf37-54rm | |
| Use of Non-Canonical URL Paths for Authorization Decisions | |
| GHSA-x8cp-jf6f-r4xh | |
| CVE-2025-14761 | |