← All credits
offset
51 vulnerability records and advisories credit this contributor.
CVE-2026-74786
Scriban before 7.0.0 Denial of Service via Unbounded Template Output
CVE-2026-74785
Scriban before 7.0.0 Denial of Service via Unbounded Resource Consumption
CVE-2026-67311
Budibase before 3.38.1 SSRF Blacklist Bypass via HTTP Redirect
CVE-2026-8630
justhtml before 1.12.0 Mutation XSS via Raw Text Elements
CVE-2026-65899
DOMPurify before 3.4.9 Trusted Types Policy State Contamination
CVE-2026-65902
DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags
CVE-2026-65911
DOMPurify before 3.4.0 XSS via ADD_ATTR/ADD_TAGS State Leakage
CVE-2026-64627
Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion
CVE-2026-56765
Vikunja - Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR
CVE-2026-56268
Flowise - Cross-Workspace Information Disclosure via chatflows/apikey Endpoint