cve.li

Recent

CVE-2026-106509CWE-94CWE-1336

Backstage: Improper validation of MkDocs theme configuration in TechDocs

Published 2026-10-06 by GitHub_M

CVE-2026-106508CWE-22CWE-59

Backstage: Potential file exposure through local TechDocs publisher

Published 2026-10-06 by GitHub_M

CVE-2026-106507CWE-59CWE-61

Backstage: TechDocs arbitrary file read via mkdocs snippets

Published 2026-10-06 by GitHub_M

CVE-2026-106506CWE-202CWE-203

Backstage: Improper input validation in scaffolder task list ordering

Published 2026-10-06 by GitHub_M

CVE-2026-106505CWE-426CWE-436

Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend

Published 2026-10-06 by GitHub_M

CVE-2026-106504CWE-532

Backstage: Sensitive information exposure in scaffolder task logs

Published 2026-10-06 by GitHub_M

CVE-2026-106503CWE-178CWE-284

Backstage: Scaffolder action input authorization bypass

Published 2026-10-06 by GitHub_M

CVE-2026-97626CWE-200

Gitea profile feed disclosure bypassing user visibility

Published 2026-10-06 by Gitea

CVE-2026-96594CWE-79

Gitea repository media API stored XSS

Published 2026-10-06 by Gitea

CVE-2026-89182CWE-863

Gitea push-to-create bypass of FORCE_PRIVATE policy

Published 2026-10-06 by Gitea

Load more ↓