Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: languages Tag: cwe-289 Clear
ID Title
CVE-2026-32639 Vulnerability in winter/wn-cms-module (CVE-2026-32639)
vulnerability in winter/wn-cms-module (CVE-2026-32639). Confidential information can be exposed externally. Exploitable via ``cms.manage_pages``. Mitigation: upgrade to `1.2.13` or later.
CVE-2026-8457 Vulnerability in wordpress (CVE-2026-8457)
vulnerability in wordpress (CVE-2026-8457). Successful exploitation can lead to full system takeover.
CVE-2026-9701 Vulnerability in wordpress (CVE-2026-9701)
vulnerability in wordpress (CVE-2026-9701). Successful exploitation can lead to full system takeover. Exploitable via ``eventer_verification_code``.
CVE-2026-48618 Vulnerability in nodejs (CVE-2026-48618)
vulnerability in nodejs (CVE-2026-48618). Confidential information can be exposed externally.
CVE-2026-44492 SSRF (Server-Side Request Forgery) in axios (CVE-2026-44492)
SSRF in axios (CVE-2026-44492). Confidential information can be exposed externally. Mitigation: upgrade to `1.16.0` or later.
CVE-2025-55130 Vulnerability in node-min (CVE-2025-55130)
vulnerability in node-min (CVE-2025-55130). Confidential information can be exposed externally. Mitigation: upgrade to `20.20.0, 22.22.0, 24.13.0, 25.3.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →