In Directus versions before 10.11.2 a high severity vulnerability CVE-2024-36128 was detected. This vulnerability allows attackers to cause a denial of service by providing a non-numeric length value to the random string generation utility, breaking the ability to generate random strings and affecting session refresh functionality. To address this issue, users should upgrade to version 10.11.2 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-36128.
Read more CMSIn Directus versions before 10.12.0 a medium severity vulnerability CVE-2024-39895 was detected. This vulnerability allows attackers to perform a denial of service (DoS) attack by sending GraphQL queries with duplicated fields, causing excessive resource consumption and impacting legitimate users. To address this issue, users should upgrade to version 10.12.0 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-39895.
Read more CMSIn Nextcloud Server and Enterprise Server versions from 25.0.0 to 30.0.1 a medium severity vulnerability CVE-2024-52517 was detected. This vulnerability allows attackers with access to an active user session to read global credentials in plain text. To address this issue, users should upgrade to Nextcloud Server versions 28.0.11, 29.0.8, or 30.0.1 and Nextcloud Enterprise Server versions 25.0.13.13, 26.0.13.9, 27.1.11.9, 28.0.11, 29.0.8, or 30.0.1. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-52517.
Read more StorageIn Directus versions before 10.13.2 a medium severity vulnerability CVE-2024-47822 was detected. This vulnerability allows attackers to gain unauthorized data access and manipulation by exploiting exposed access tokens in system logs. To address this issue, users should upgrade to version 10.13.2 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-47822.
Read more CMSIn Kanboard versions 1.2.48 and below a critical severity vulnerability CVE-2026-21881 was detected. This vulnerability allows attackers to bypass authentication and impersonate any user, including administrators, by sending spoofed HTTP headers when REVERSE_PROXY_AUTH is enabled, as the application does not verify that requests originate from a trusted reverse proxy. To address this issue, users should upgrade Kanboard to version 1.2.49. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21881.
Read more Project ManagementIn Kanboard versions 1.2.48 and below a medium severity vulnerability CVE-2026-21880 was detected. This vulnerability allows attackers to exploit improper input sanitization in the LDAP authentication mechanism to perform LDAP injection, enabling user enumeration and disclosure of sensitive LDAP user attributes. To address this issue, users should upgrade Kanboard to version 1.2.49. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21880.
Read more Project ManagementIn Kanboard versions 1.2.48 and below a medium severity vulnerability CVE-2026-21879 was detected. This vulnerability allows attackers to perform open redirect attacks by abusing protocol-relative URLs (e.g., //evil.com) that bypass URL validation, redirecting authenticated users to attacker-controlled websites. To address this issue, users should upgrade Kanboard to version 1.2.49. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21879.
Read more Project ManagementIn OpenLDAP LMDB mdb_load versions 2.6.10 and prior a high severity vulnerability CVE-2026-22185 was detected. This vulnerability allows local attackers to trigger a heap buffer underflow in the readline() function by supplying malformed input, resulting in an out-of-bounds read of heap memory. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-22185.
Read more SecurityIn the Page Keys plugin for WordPress versions up to and including 1.3.3 a medium severity vulnerability CVE-2025-15000 was detected. This vulnerability allows authenticated attackers with administrator-level access to inject arbitrary web scripts via the page_key parameter due to insufficient input sanitization and output escaping, resulting in stored cross-site scripting (XSS). Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-15000.
Read more CMS