<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Vue (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/vue.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/vue-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Vue (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:37 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-43900 – DeepChat is an open-source artificial intelligence agent platform that unifies m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43900</guid>
    <pubDate>Mon, 11 May 2026 23:20:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-43900</strong></p>
  <p>DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepancy between the backend validation layer and the frontend browser rendering engine. The SVGSanitizer (src/main/lib/svgSanitizer.ts) restricts script execution by scrubbing javascript: protocols using pl…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7710 – A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7710</guid>
    <pubDate>Mon, 04 May 2026 00:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7710</strong></p>
  <p>A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the file JwtAuthenticationTokenFilter.java of the component Ruoyi-Vue-Pro. Performing a manipulation of the argument mock-token results in improper authentication. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34404 – Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34404</guid>
    <pubDate>Tue, 31 Mar 2026 22:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34404</strong></p>
  <p>Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a Denial of Service (DoS) vulnerability. The issue arises because there is no restriction on the width and height parameters of the generated image. The vulnerability was reproduced using the standard configuration a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33664 – Kestra is an open-source, event-driven orchestration platform Versions up to and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33664</guid>
    <pubDate>Thu, 26 Mar 2026 22:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33664</strong></p>
  <p>Kestra is an open-source, event-driven orchestration platform Versions up to and including 1.3.3 render user-supplied flow YAML metadata fields — description, inputs[].displayName, inputs[].description — through the Markdown.vue component instantiated with html: true. The resulting HTML is injected into the DOM via Vue's v-html without any sanitization. This allows a flow author to embed arbitrar…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33336 – Vikunja is an open-source self-hosted task management platform. Starting in vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33336</guid>
    <pubDate>Tue, 24 Mar 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33336</strong></p>
  <p>Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the main BrowserWindow and does not restrict same-window navigations. An attacker who can place a link in user-generated content (task descriptions, comments, project descriptions) can cause the BrowserWindow to na…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29082 – Kestra is an event-driven orchestration platform. In versions from 1.1.10 and pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29082</guid>
    <pubDate>Fri, 06 Mar 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29082</strong></p>
  <p>Kestra is an event-driven orchestration platform. In versions from 1.1.10 and prior, Kestra’s execution-file preview renders user-supplied Markdown (.md) with markdown-it instantiated as html:true and injects the resulting HTML with Vue’s v-html without sanitisation. At time of publication, there are no publicly available patches.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22786 – Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-adm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22786</guid>
    <pubDate>Mon, 12 Jan 2026 22:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22786</strong></p>
  <p>Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.8.7 has a path traversal vulnerability in the breakpoint resume upload functionality. Attacker can upload any files on any directory. In the breakpoint_continue.go file, the MakeFile function accepts a fileName parameter through the /fileUploadAndDownload/breakpointContinueFinish API endpoint and directly con…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22786">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66916 – The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66916</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66916</guid>
    <pubDate>Thu, 08 Jan 2026 20:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66916</strong></p>
  <p>The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66916">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66481 – DeepChat is an open-source AI chat platform that supports cloud models and LLMs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66481</guid>
    <pubDate>Tue, 09 Dec 2025 01:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66481</strong></p>
  <p>DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable to XSS attacks through improperly sanitized Mermaid content. The recent security patch for MermaidArtifact.vue is insufficient and can be bypassed using unquoted HTML attributes combined with HTML entity encoding. Remote Code Execution is possible on the victim's machine via th…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66410 – Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66410</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66410</guid>
    <pubDate>Mon, 01 Dec 2025 23:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66410</strong></p>
  <p>Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66410">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-60354 – Unauthorized modification of arbitrary articles vulnerability exists in blog-vue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60354</guid>
    <pubDate>Tue, 28 Oct 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-60354</strong></p>
  <p>Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60354">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-59053 – AIRI is a self-hosted, artificial intelligence based Grok Companion. In v0.7.2-b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59053</guid>
    <pubDate>Thu, 11 Sep 2025 19:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-59053</strong></p>
  <p>AIRI is a self-hosted, artificial intelligence based Grok Companion. In v0.7.2-beta.2 in the `packages/stage-ui/src/components/MarkdownRenderer.vue` path, the Markdown content is processed using the useMarkdown composable, and the processed HTML is rendered directly into the DOM using v-html. An attacker creates a card file containing malicious HTML/JavaScript, then simply processes it using the…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54075 – MDC is a tool to take regular Markdown and write documents interacting deeply wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54075</guid>
    <pubDate>Fri, 18 Jul 2025 16:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54075</strong></p>
  <p>MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.17.2, a remote script-inclusion / stored cross-site scripting vulnerability in @nuxtjs/mdc lets a Markdown author inject a `<base href="https://attacker.tld">` element. The `<base>` tag rewrites how all subsequent relative URLs are resolved, so an attacker can make the page load…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-55028 – A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55028</guid>
    <pubDate>Tue, 25 Mar 2025 21:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-55028</strong></p>
  <p>A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via uploading a crafted Vue file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27415 – Nuxt is an open-source web development framework for Vue.js. Prior to 3.16.0, by...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27415</guid>
    <pubDate>Wed, 19 Mar 2025 19:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27415</strong></p>
  <p>Nuxt is an open-source web development framework for Vue.js. Prior to 3.16.0, by sending a crafted HTTP request to a server behind an CDN, it is possible in some circumstances to poison the CDN cache and highly impacts the availability of a site. It is possible to craft a request, such as https://mysite.com/?/_payload.json which will be rendered as JSON. If the CDN in front of a Nuxt site ignores…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-349</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27597 – Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27597</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27597</guid>
    <pubDate>Fri, 07 Mar 2025 16:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27597</strong></p>
  <p>Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, causing denial of service (DoS) a the minimum consequence. Moreover, the cons…</p>
  <p><strong>CVSS:</strong> 8.9 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27597">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-25570 – Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25570</guid>
    <pubDate>Thu, 27 Feb 2025 22:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-25570</strong></p>
  <p>Vue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-24981 – MDC is a tool to take regular Markdown and write documents interacting deeply wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24981</guid>
    <pubDate>Thu, 06 Feb 2025 18:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-24981</strong></p>
  <p>MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. In affected versions unsafe parsing logic of the URL from markdown can lead to arbitrary JavaScript code due to a bypass to the existing guards around the `javascript:` protocol scheme in the URL. The parsing logic implement in `props.ts` maintains a deny-list approach to filtering potential malici…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-42352 – Nuxt is a free and open-source framework to create full-stack web applications a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42352</guid>
    <pubDate>Mon, 05 Aug 2024 21:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-42352</strong></p>
  <p>Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. `nuxt/icon` provides an API to allow client side icon lookup. This endpoint is at `/api/_nuxt_icon/[name]`. The proxied request path is improperly parsed, allowing an attacker to change the scheme and host of the request. This leads to SSRF, and could potentially lead to sensitive data exposur…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34344 – Nuxt is a free and open-source framework to create full-stack web applications a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34344</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34344</guid>
    <pubDate>Mon, 05 Aug 2024 21:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34344</strong></p>
  <p>Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `path` parameter in the NuxtTestComponentWrapper, an attacker can execute arbitrary JavaScript on the server side, which allows them to execute arbitrary commands. Users who open a malicious web page in the browser while running the test locally are af…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34344">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23657 – Nuxt is a free and open-source framework to create full-stack web applications a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23657</guid>
    <pubDate>Mon, 05 Aug 2024 21:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23657</strong></p>
  <p>Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on the `getTextAssetContent` RPC function which is vulnerable to path traversal.  Combined with a lack of Origin checks on the WebSocket handler,  an attacker is able to interact with a locally running devtools instance and exfiltrate data abusing this v…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-41809 – OpenObserve is an open-source observability platform. Starting in version 0.4.4 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41809</guid>
    <pubDate>Thu, 25 Jul 2024 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-41809</strong></p>
  <p>OpenObserve is an open-source observability platform. Starting in version 0.4.4 and prior to version 0.10.0, OpenObserve contains a cross-site scripting vulnerability in line 32 of `openobserve/web/src/views/MemberSubscription.vue`. Version 0.10.0 sanitizes incoming html.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-41808 – The OpenObserve open-source observability platform provides the ability to filte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41808</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41808</guid>
    <pubDate>Thu, 25 Jul 2024 20:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-41808</strong></p>
  <p>The OpenObserve open-source observability platform provides the ability to filter logs in a dashboard by the values uploaded in a given log. However, all versions of the platform through 0.9.1 do not sanitize user input in the filter selection menu, which may result in complete account takeover. It has been noted that the front-end uses `DOMPurify` or Vue templating to escape cross-site scripting…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41808">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-23998 – goanother Another Redis Desktop Manager =&lt;1.6.1 is vulnerable to Cross Site Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23998</guid>
    <pubDate>Fri, 05 Jul 2024 16:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-23998</strong></p>
  <p>goanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.vue.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37896 – Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-adm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37896</guid>
    <pubDate>Mon, 17 Jun 2024 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37896</strong></p>
  <p>Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.6.5 has SQL injection vulnerability. The SQL injection vulnerabilities occur when a web application allows users to input data into SQL queries without sufficiently validating or sanitizing the input. Failing to properly enforce restrictions on user input could mean that even a basic form input field can be u…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49781 – NocoDB is software for building databases as spreadsheets. Prior to 0.202.9, a s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49781</guid>
    <pubDate>Tue, 14 May 2024 14:06:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49781</strong></p>
  <p>NocoDB is software for building databases as spreadsheets. Prior to 0.202.9, a stored cross-site scripting vulnerability exists within the Formula virtual cell comments functionality. The nc-gui/components/virtual-cell/Formula.vue displays a v-html tag with the value of "urls" whose contents are processed by the function replaceUrlsWithLink(). This function recognizes the pattern URI::(XXX) and c…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-31457 – gin-vue-admin is a backstage management system based on vue and gin, which separ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-31457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-31457</guid>
    <pubDate>Tue, 09 Apr 2024 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-31457</strong></p>
  <p>gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. gin-vue-admin pseudoversion 0.0.0-20240407133540-7bc7c3051067, corresponding to version 2.6.1, has a code injection vulnerability in the backend. In the Plugin System -> Plugin Template feature, an attacker can perform directory traversal by manipulating the `plugName` parame…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-31457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-27917 – Shopware is an open commerce platform based on Symfony Framework and Vue. The Sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27917</guid>
    <pubDate>Wed, 06 Mar 2024 20:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-27917</strong></p>
  <p>Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session Cookie and assigns it to the Response. Since Shopware 6.5.8.0, the 404 pages are cached to improve the performance of 404 pages. So the cached Response which contains a Session Cookie when the Browser accessing the 404 page, has no cookies yet. The Symfony Session Handler is in u…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-524</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-40020 – PrivateUploader is an open source image hosting server written in Vue and TypeSc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40020</guid>
    <pubDate>Mon, 14 Aug 2023 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-40020</strong></p>
  <p>PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v3/admin.controller.ts` did not correctly verify whether the user was an administrator (High Level) or moderator (Low Level) causing the request to continue processing. The response would be a 403 with ADMIN_ONLY, however, next() would call leading to any updates/changes in the r…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-47762 – In gin-vue-admin &lt; 2.5.5, the download module has a Path Traversal vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-47762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-47762</guid>
    <pubDate>Fri, 03 Feb 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-47762</strong></p>
  <p>In gin-vue-admin < 2.5.5, the download module has a Path Traversal vulnerability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47762">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-22731 – Shopware is an open source commerce platform based on Symfony Framework and Vue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22731</guid>
    <pubDate>Tue, 17 Jan 2023 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-22731</strong></p>
  <p>Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`, `filter`, `sort`. This allows a template to call any global PHP function and thus execute arbitrary code. The attacker must have access to a Twig environment in order to exploit this vulner…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-39345 – Gin-vue-admin is a backstage management system based on vue and gin, which separ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39345</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39345</guid>
    <pubDate>Tue, 25 Oct 2022 17:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-39345</strong></p>
  <p>Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin prior to 2.5.4 is vulnerable to path traversal, which leads to file upload vulnerabilities. Version 2.5.4 contains a patch for this issue. There are no workarounds aside from upgrading to a patched version.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39345">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-39305 – Gin-vue-admin is a backstage management system based on vue and gin, which separ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39305</guid>
    <pubDate>Mon, 24 Oct 2022 14:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-39305</strong></p>
  <p>Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Versions prior to 2.5.4 contain a file upload ability. The affected code fails to validate fileMd5 and fileName parameters, resulting in an arbitrary file being read. This issue is patched in 2.5.4b. There are no known workarounds.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-32176 – In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestrict...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32176</guid>
    <pubDate>Mon, 17 Oct 2022 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-32176</strong></p>
  <p>In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin's cookie leading to account takeover.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-32177 – In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32177</guid>
    <pubDate>Fri, 14 Oct 2022 07:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-32177</strong></p>
  <p>In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin’s cookie leading to account takeover.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24872 – Shopware is an open commerce platform based on Symfony Framework and Vue. Permis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24872</guid>
    <pubDate>Wed, 20 Apr 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24872</strong></p>
  <p>Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable within normal user session. Users are advised to update to the current version 6.4.10.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. There are no known workarounds for this issue.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24871 – Shopware is an open commerce platform based on Symfony Framework and Vue. In aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24871</guid>
    <pubDate>Wed, 20 Apr 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24871</strong></p>
  <p>Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on the server to read or update internal resources. Users are advised to update to the current version 6.4.10.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. There are no known workarounds for…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24843 – Gin-vue-admin is a backstage management system based on vue and gin, which separ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24843</guid>
    <pubDate>Wed, 13 Apr 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24843</strong></p>
  <p>Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin 2.50 has arbitrary file read vulnerability due to a lack of parameter validation. This has been resolved in version 2.5.1. There are no known workarounds for this issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24844 – Gin-vue-admin is a backstage management system based on vue and gin, which separ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24844</guid>
    <pubDate>Wed, 13 Apr 2022 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24844</strong></p>
  <p>Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. The problem occurs in the following code in server/service/system/sys_auto_code_pgsql.go, which means that PostgreSQL must be used as the database for this vulnerability to occur. Users must: Require JWT login） and be using PostgreSQL to be affected. This issue has been resol…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-33022 – Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-cri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33022</guid>
    <pubDate>Fri, 01 Apr 2022 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-33022</strong></p>
  <p>Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-33020 – Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or passwor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33020</guid>
    <pubDate>Fri, 01 Apr 2022 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-33020</strong></p>
  <p>Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-324</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-33018 – The use of a broken or risky cryptographic algorithm in Philips Vue PACS version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33018</guid>
    <pubDate>Fri, 01 Apr 2022 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-33018</strong></p>
  <p>The use of a broken or risky cryptographic algorithm in Philips Vue PACS versions 12.2.x.x and prior is an unnecessary risk that may result in the exposure of sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-27501 – Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rule...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27501</guid>
    <pubDate>Fri, 01 Apr 2022 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-27501</strong></p>
  <p>Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-710</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-21660 – Gin-vue-admin is a backstage management system based on vue and gin. In versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21660</guid>
    <pubDate>Wed, 09 Feb 2022 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-21660</strong></p>
  <p>Gin-vue-admin is a backstage management system based on vue and gin. In versions prior to 2.4.7 low privilege users are able to modify higher privilege users. Authentication is missing on the `setUserInfo` function. Users are advised to update as soon as possible. There are no known workarounds.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-44219 – Gin-Vue-Admin before 2.4.6 mishandles a SQL database.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-44219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-44219</guid>
    <pubDate>Wed, 24 Nov 2021 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-44219</strong></p>
  <p>Gin-Vue-Admin before 2.4.6 mishandles a SQL database.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21383 – Wiki.js an open-source wiki app built on Node.js. Wiki.js before version 2.5.191...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21383</guid>
    <pubDate>Thu, 18 Mar 2021 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21383</strong></p>
  <p>Wiki.js an open-source wiki app built on Node.js. Wiki.js before version 2.5.191 is vulnerable to stored cross-site scripting through mustache expressions in code blocks. This vulnerability exists due to mustache expressions being parsed by Vue during content injection even though it is contained within a `<pre>` element. By creating a crafted wiki page, a malicious Wiki.js user may stage a store…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36154 – The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36154</guid>
    <pubDate>Mon, 04 Jan 2021 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36154</strong></p>
  <p>The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" directory, which allows local users to obtain administrative privileges via a Trojan horse application.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-1999-1134 – Vulnerability in Vue 3.0 in HP 9.x allows local users to gain root privileges, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-1134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-1134</guid>
    <pubDate>Wed, 18 May 1994 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-1999-1134</strong></p>
  <p>Vulnerability in Vue 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4038, PHSS_4055, and PHSS_4066.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-1134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-1999-1135 – Vulnerability in VUE 3.0 in HP 9.x allows local users to gain root privileges, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-1135</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-1135</guid>
    <pubDate>Wed, 20 Apr 1994 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-1999-1135</strong></p>
  <p>Vulnerability in VUE 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4994 and PHSS_5438.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-1135">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
