Products: 3
Vulnerabilities: 25
Known Exploited: 0
6
Critical Level Threats
11
High Level Threats
7
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-55086
Etherpad: Import/export use Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
Last Modified: Aug 25, 2026
Published: Aug 19, 2026
CVE-2026-55085
Etherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-lite
Last Modified: Aug 21, 2026
Published: Aug 19, 2026
CVE-2026-55089
Etherpad: JWT `admin` claim presence-only check lets non-admin OAuth users invoke every Etherpad HTTP API endpoint
Last Modified: Aug 21, 2026
Published: Aug 19, 2026
CVE-2026-55090
Etherpad: Stored XSS in HTML export via unescaped attribute-pool values
Last Modified: Aug 21, 2026
Published: Aug 19, 2026
CVE-2026-55088
Etherpad: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
Last Modified: Aug 21, 2026
Published: Aug 19, 2026
Items Per Page
