Vendor CVEs
Lumiverse
All CVEs
83 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-16775 | Hig | 0.43 | 7.7 | 0.03 | Dec 13, 2019 | Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would… | ||
| CVE-2024-36527 | Med | 0.42 | 6.5 | 0.03 | Jun 17, 2024 | puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file protocol to read sensitive information from the server. | ||
| CVE-2022-29244 | Hig | 0.42 | 7.5 | 0.04 | Jun 13, 2022 | npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively,… | ||
| CVE-2020-7684 | Hig | 0.42 | 7.5 | 0.01 | Jul 17, 2020 | This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation. | ||
| CVE-2024-38990 | Med | 0.41 | 6.3 | 0.00 | Jul 1, 2024 | Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | ||
| CVE-2020-7788 | Hig | 0.41 | 7.3 | 0.04 | Dec 11, 2020 | This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context. | ||
| CVE-2020-7747 | Med | 0.41 | 6.3 | 0.01 | Oct 20, 2020 | This affects all versions of package lightning-server. It is possible to inject malicious JavaScript code as part of a session controller. | ||
| CVE-2026-47903 | Med | 0.40 | 6.2 | 0.00 | Jun 9, 2026 | CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does… | ||
| CVE-2019-19466 | Med | 0.40 | 6.1 | 0.01 | Dec 5, 2019 | SCEditor 2.1.3 allows XSS. | ||
| CVE-2018-20524 | Med | 0.40 | 6.1 | 0.01 | Dec 27, 2018 | The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of < in a message, because a danmuWrapper DIV element in chatbox-only\danmu.js is outside the scope of a Content Security Policy (CSP). | ||
| CVE-2018-17046 | Med | 0.40 | 6.1 | 0.01 | Sep 14, 2018 | translate man before 2018-08-21 has XSS via containers/outputBox/outputBox.vue and store/index.js. | ||
| CVE-2017-16087 | hig | 0.38 | — | — | May 29, 2019 | ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-wp3j-gv53-4pg8. This link is maintained to preserve external references. ## Original Description Affected versions of `fs-git` do not sanitize strings passed into the `buildCommand` method,… | ||
| CVE-2026-11232 | Med | 0.35 | 5.4 | 0.00 | Jun 4, 2026 | Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low) | ||
| CVE-2021-23411 | Med | 0.35 | 5.4 | 0.01 | Jul 21, 2021 | Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the main functionality. It accepts input that can result in the output (an anchor a tag) containing undesirable Javascript code that can be executed upon user interaction. | ||
| CVE-2020-7779 | Med | 0.35 | 5.3 | 0.02 | Nov 26, 2020 | All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted invalid emails - for example, --@------------------------------------------------------------------------------------------------------------------------!. | ||
| CVE-2020-7618 | Med | 0.35 | 5.3 | 0.01 | Apr 7, 2020 | sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of the 'Object.prototype' by abusing the 'set' function located in 'js/set.js'. | ||
| CVE-2020-7616 | Med | 0.35 | 5.3 | 0.01 | Apr 7, 2020 | express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack… | ||
| CVE-2018-10178 | Med | 0.35 | 5.3 | 0.01 | Apr 17, 2018 | The FromDocToPDF extension before 13.611.13.2303 for Chrome allows remote attackers to discover visited web sites via vectors involving a mostVisitedSites command. | ||
| CVE-2014-125128 | Med | 0.33 | 6.1 | 0.00 | Sep 8, 2025 | 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in anchor tags (``), allowing bypasses that contain different casings, whitespace characters, or… | ||
| CVE-2015-9286 | Med | 0.33 | 6.1 | 0.01 | Apr 30, 2019 | Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS. | ||
| CVE-2015-9282 | Med | 0.33 | 6.1 | 0.01 | Feb 6, 2019 | The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote unauthenticated access to the dashboard. | ||
| CVE-2026-44443 | Med | 0.31 | 4.8 | 0.00 | May 26, 2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level variable is set and unexpired. It does not validate any value from the incoming HTTP request or bind the nonce to the admin's session. If the admin's… | ||
| CVE-2024-25503 | Med | 0.31 | 4.7 | 0.01 | Apr 4, 2024 | Cross Site Scripting (XSS) vulnerability in Advanced REST Client v.17.0.9 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script to the edit details parameter of the New Project function. | ||
| CVE-2026-53606 | Med | 0.28 | 5.4 | 0.00 | Jun 12, 2026 | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Versions of sanitize-html prior to 2.17.5 use `allowedSchemesAppliedToAttributes` (default: `['href', 'src', 'cite']`) to gate the… | ||
| CVE-2026-9467 | Med | 0.28 | 4.3 | 0.00 | May 25, 2026 | A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of the file src/server.ts. The manipulation leads to path traversal. The attack is possible to be carried out remotely. The exploit is publicly available and… | ||
| CVE-2022-25869 | Med | 0.28 | 4.2 | 0.07 | Jul 15, 2022 | All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of elements. | ||
| CVE-2020-7696 | Med | 0.28 | 5.3 | 0.02 | Jul 17, 2020 | This affects all versions of package react-native-fast-image. When an image with source={{uri: "...", headers: { host: "somehost.com", authorization: "..." }} is loaded, all other subsequent images will use the same headers, this can lead to signing credentials or other session… | ||
| CVE-2016-1000224 | med | 0.26 | — | 0.00 | Sep 1, 2020 | Affected versions of `ezseed-transmission` download and run a script over an HTTP connection. An attacker in a privileged network position could launch a Man-in-the-Middle attack and intercept the script, replacing it with malicious code, completely compromising the system… | ||
| CVE-2014-8881 | med | 0.26 | — | 0.02 | Sep 1, 2020 | All versions of the `bleach` package are vulnerable to a regular expression denial of service attack when certain types of input are passed into the sanitize function. ## Recommendation The `bleach` package is not currently maintained, and has not seen an update since 2014. … | ||
| CVE-2014-8883 | med | 0.26 | — | 0.01 | Aug 31, 2020 | All versions of the static file server module nhouston are vulnerable to directory traversal. An attacker can provide input such as `../` to read files outside of the served directory. ## Recommendation It is recommended that a different module be used, as we have been unable… | ||
| CVE-2020-15095 | Med | 0.22 | 4.4 | 0.00 | Jul 7, 2020 | Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "://[[:]@][:][:][/]". The password value is not redacted and is printed to stdout and… | ||
| CVE-2026-11686 | Low | 0.20 | 3.1 | 0.00 | Jun 9, 2026 | Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2020-28448 | Med | 0.00 | 5.6 | 0.01 | Dec 22, 2020 | This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array. |
- risk 0.43cvss 7.7epss 0.03
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would…
- risk 0.42cvss 6.5epss 0.03
puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file protocol to read sensitive information from the server.
- risk 0.42cvss 7.5epss 0.04
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively,…
- risk 0.42cvss 7.5epss 0.01
This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.
- risk 0.41cvss 6.3epss 0.00
Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- risk 0.41cvss 7.3epss 0.04
This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.
- risk 0.41cvss 6.3epss 0.01
This affects all versions of package lightning-server. It is possible to inject malicious JavaScript code as part of a session controller.
- risk 0.40cvss 6.2epss 0.00
CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does…
- risk 0.40cvss 6.1epss 0.01
SCEditor 2.1.3 allows XSS.
- risk 0.40cvss 6.1epss 0.01
The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of < in a message, because a danmuWrapper DIV element in chatbox-only\danmu.js is outside the scope of a Content Security Policy (CSP).
- risk 0.40cvss 6.1epss 0.01
translate man before 2018-08-21 has XSS via containers/outputBox/outputBox.vue and store/index.js.
- risk 0.38cvss —epss —
## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-wp3j-gv53-4pg8. This link is maintained to preserve external references. ## Original Description Affected versions of `fs-git` do not sanitize strings passed into the `buildCommand` method,…
- risk 0.35cvss 5.4epss 0.00
Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
- risk 0.35cvss 5.4epss 0.01
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the main functionality. It accepts input that can result in the output (an anchor a tag) containing undesirable Javascript code that can be executed upon user interaction.
- risk 0.35cvss 5.3epss 0.02
All versions of package djvalidator are vulnerable to Regular Expression Denial of Service (ReDoS) by sending crafted invalid emails - for example, --@------------------------------------------------------------------------------------------------------------------------!.
- risk 0.35cvss 5.3epss 0.01
sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of the 'Object.prototype' by abusing the 'set' function located in 'js/set.js'.
- risk 0.35cvss 5.3epss 0.01
express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack…
- risk 0.35cvss 5.3epss 0.01
The FromDocToPDF extension before 13.611.13.2303 for Chrome allows remote attackers to discover visited web sites via vectors involving a mostVisitedSites command.
- risk 0.33cvss 6.1epss 0.00
'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in anchor tags (``), allowing bypasses that contain different casings, whitespace characters, or…
- risk 0.33cvss 6.1epss 0.01
Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.
- risk 0.33cvss 6.1epss 0.01
The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote unauthenticated access to the dashboard.
- risk 0.31cvss 4.8epss 0.00
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level variable is set and unexpired. It does not validate any value from the incoming HTTP request or bind the nonce to the admin's session. If the admin's…
- risk 0.31cvss 4.7epss 0.01
Cross Site Scripting (XSS) vulnerability in Advanced REST Client v.17.0.9 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script to the edit details parameter of the New Project function.
- risk 0.28cvss 5.4epss 0.00
ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Versions of sanitize-html prior to 2.17.5 use `allowedSchemesAppliedToAttributes` (default: `['href', 'src', 'cite']`) to gate the…
- risk 0.28cvss 4.3epss 0.00
A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of the file src/server.ts. The manipulation leads to path traversal. The attack is possible to be carried out remotely. The exploit is publicly available and…
- risk 0.28cvss 4.2epss 0.07
All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of elements.
- risk 0.28cvss 5.3epss 0.02
This affects all versions of package react-native-fast-image. When an image with source={{uri: "...", headers: { host: "somehost.com", authorization: "..." }} is loaded, all other subsequent images will use the same headers, this can lead to signing credentials or other session…
- risk 0.26cvss —epss 0.00
Affected versions of `ezseed-transmission` download and run a script over an HTTP connection. An attacker in a privileged network position could launch a Man-in-the-Middle attack and intercept the script, replacing it with malicious code, completely compromising the system…
- risk 0.26cvss —epss 0.02
All versions of the `bleach` package are vulnerable to a regular expression denial of service attack when certain types of input are passed into the sanitize function. ## Recommendation The `bleach` package is not currently maintained, and has not seen an update since 2014. …
- risk 0.26cvss —epss 0.01
All versions of the static file server module nhouston are vulnerable to directory traversal. An attacker can provide input such as `../` to read files outside of the served directory. ## Recommendation It is recommended that a different module be used, as we have been unable…
- risk 0.22cvss 4.4epss 0.00
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "://[[:]@][:][:][/]". The password value is not redacted and is printed to stdout and…
- risk 0.20cvss 3.1epss 0.00
Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
- risk 0.00cvss 5.6epss 0.01
This affects the package multi-ini before 2.1.1. It is possible to pollute an object's prototype by specifying the proto object as part of an array.
Page 2 of 2