VYPR
Vendor

Algernon Project

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2023-26131MedMay 31, 2023
    risk 0.35cvss 5.4epss 0.01

    All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerable to Cross-site Scripting (XSS) via the themes.NoPage(filename, theme) function due to improper user input sanitization. Exploiting this…

  • CVE-2025-65754MedDec 10, 2025
    risk 0.33cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in Algernon v1.17.4 allows attackers to execute arbitrary code via injecting a crafted payload into a filename.