Authenticated (Author+) Stored CrossSite Scripting via SVG File Upload vulnerability
12 February, 2025
Authenticated (Contributor+) Arbitrary File Upload via storeUploads vulnerability
12 February, 2025
CrossSite Request Forgery vulnerability
8 August, 2024
Authenticated (Contributor+) Arbitrary File Upload vulnerability
18 July, 2024
Missing Authorization to Authenticated (Contributor+) Post Modification vulnerability
16 July, 2024