Open Source Vulnerabilities
kubernetes-csi-external-attacher-fips
kubernetes-csi-livenessprobe-fips
grafana-pcp
Important: grafana-pcp security update
YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize
YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize
YesWiki Authenticated SQL Injection in ReactionManager
Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki
Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki
Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki
Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` in YesWiki
YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.hint` in attribute and label-body contexts — stored XSS in form renders (sibling class of commit `e6b66aa`)
YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.hint` in attribute and label-body contexts — stored XSS in form renders (sibling class of commit `e6b66aa`)
YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)
YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in yeswiki/yeswiki
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in yeswiki/yeswiki
YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`
YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`
