Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
MINI-x924-whjr-9g39 MINI-x924-whjr-9g39
MINI-7277-6wp3-wfmv MINI-7277-6wp3-wfmv
MINI-j77x-868w-frr6 MINI-j77x-868w-frr6
MINI-5hpq-82jx-6v5m MINI-5hpq-82jx-6v5m
MINI-g6xq-p8mp-w5fh MINI-g6xq-p8mp-w5fh
MINI-5rc9-3ww9-6rf3 MINI-5rc9-3ww9-6rf3
MINI-w58r-37wm-39q5 MINI-w58r-37wm-39q5
MINI-j8vp-57wg-c2m3 MINI-j8vp-57wg-c2m3
MINI-c9xm-qxvc-gqrp MINI-c9xm-qxvc-gqrp
MINI-qh5w-wv3v-pw57 MINI-qh5w-wv3v-pw57
MINI-f6wq-pxxc-5g6r MINI-f6wq-pxxc-5g6r
MINI-jvp7-mpxq-xgg4 MINI-jvp7-mpxq-xgg4
MINI-mfwc-hqfv-c7cw MINI-mfwc-hqfv-c7cw
MINI-rc4j-736h-p8wr MINI-rc4j-736h-p8wr
MINI-9qrq-x9f4-p9pr MINI-9qrq-x9f4-p9pr
MINI-4x3c-jr92-fjx4 MINI-4x3c-jr92-fjx4
MINI-6cmp-9cqc-g9j3 MINI-6cmp-9cqc-g9j3
MINI-7425-wwpc-w9fx MINI-7425-wwpc-w9fx
MINI-v8fj-rmfr-ffj7 MINI-v8fj-rmfr-ffj7
MINI-9fgx-xw8p-8xhv MINI-9fgx-xw8p-8xhv
MINI-59fp-gm3c-xxfc MINI-59fp-gm3c-xxfc
MINI-x8x4-pqwv-mj2q MINI-x8x4-pqwv-mj2q
MINI-g9cj-8353-j6p4 MINI-g9cj-8353-j6p4
MINI-5p85-xhvh-74rm MINI-5p85-xhvh-74rm
MINI-wxr8-m859-4cwf MINI-wxr8-m859-4cwf
MINI-fmxm-hmcx-4crm MINI-fmxm-hmcx-4crm
MINI-5273-3r85-6wg3 MINI-5273-3r85-6wg3
CVE-2026-53639 Vulnerability in sylius/sylius (CVE-2026-53639)
vulnerability in sylius/sylius (CVE-2026-53639). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v2/shop/payment-requests/{hash}`. Mitigation: upgrade to `2.2.6` or later.
CVE-2026-53638 Authorization Flaw in sylius/sylius (CVE-2026-53638)
vulnerability in sylius/sylius (CVE-2026-53638). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /api/v2/shop/account/orders/{tokenValue}/payments/{paymentId}`. Mitigation: upgrade to `2.2.6` or later.
CVE-2026-53637 Vulnerability in sylius/sylius (CVE-2026-53637)
vulnerability in sylius/sylius (CVE-2026-53637). Data can be tampered with by attackers. Exploitable via ``sylius_shop.twig.component.cart.form``. Mitigation: upgrade to `2.2.6` or later.
CVE-2026-52777 Cross-Site Request Forgery (CSRF) in yeswiki/yeswiki (CVE-2026-52777)
vulnerability in yeswiki/yeswiki (CVE-2026-52777). Risk of unauthorized operations or information disclosure. Exploitable via ``__toString``. Mitigation: upgrade to `4.6.6` or later.
CVE-2026-52775 SQL Injection in yeswiki/yeswiki (CVE-2026-52775)
SQL injection in yeswiki/yeswiki (CVE-2026-52775). Successful exploitation can lead to full system takeover. Exploitable via `DELETE /wiki/`. Mitigation: upgrade to `4.6.6` or later.
CGA-6hp4-wmm6-xmhx CGA-6hp4-wmm6-xmhx
CGA-2pq2-9pxf-cx2v CGA-2pq2-9pxf-cx2v
CGA-6gq4-7j23-q32x CGA-6gq4-7j23-q32x
CVE-2026-52774 Vulnerability in yeswiki/yeswiki (CVE-2026-52774)
vulnerability in yeswiki/yeswiki (CVE-2026-52774). Risk of unauthorized operations or information disclosure. Exploitable via ``GET``. Mitigation: upgrade to `4.6.6` or later.
CGA-989q-cj77-mfj4 CGA-989q-cj77-mfj4
CGA-p6mr-jp48-f5w4 CGA-p6mr-jp48-f5w4
CVE-2026-52773 Vulnerability in yeswiki/yeswiki (CVE-2026-52773)
vulnerability in yeswiki/yeswiki (CVE-2026-52773). Risk of unauthorized operations or information disclosure. Exploitable via ``time``. Mitigation: upgrade to `4.6.6` or later.
CGA-73vv-v952-w33p CGA-73vv-v952-w33p
CVE-2026-52772 Vulnerability in yeswiki/yeswiki (CVE-2026-52772)
vulnerability in yeswiki/yeswiki (CVE-2026-52772). Risk of unauthorized operations or information disclosure. Exploitable via ``field.label``. Mitigation: upgrade to `4.6.6` or later.
CGA-pfh4-493r-7grq CGA-pfh4-493r-7grq
CGA-vmf9-6g69-cr86 CGA-vmf9-6g69-cr86
CGA-hwpx-w437-xc4c CGA-hwpx-w437-xc4c
CGA-h7r2-rvm8-qp8v CGA-h7r2-rvm8-qp8v
CGA-x32j-mgqx-57q3 CGA-x32j-mgqx-57q3
CVE-2026-52771 SQL Injection in yeswiki/yeswiki (CVE-2026-52771)
SQL injection in yeswiki/yeswiki (CVE-2026-52771). Confidential information can be exposed externally. Exploitable via `POST /api/pages/{tag}`. Mitigation: upgrade to `4.6.6` or later.
CVE-2026-52770 SQL Injection in yeswiki/yeswiki (CVE-2026-52770)
SQL injection in yeswiki/yeswiki (CVE-2026-52770). Confidential information can be exposed externally. Exploitable via ``query``. Mitigation: upgrade to `4.6.6` or later.
CVE-2026-52769 SSRF (Server-Side Request Forgery) in yeswiki/yeswiki (CVE-2026-52769)
SSRF in yeswiki/yeswiki (CVE-2026-52769). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/forms/{formId}/actor/inbox`. Mitigation: upgrade to `4.6.6` or later.
CVE-2026-52767 Vulnerability in yeswiki/yeswiki (CVE-2026-52767)
vulnerability in yeswiki/yeswiki (CVE-2026-52767). Data can be tampered with by attackers. Exploitable via `POST /api/forms/{enabled-form-id}/actor/inbox`. Mitigation: upgrade to `4.6.6` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →