content
82 known vulnerabilities · 0 critical · 7 high
@webiny/react-rich-text-renderer vulnerable to insecure rendering of rich text content
Hono allows bypass of CSRF Middleware by a request without Content-Type header.
Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation
Malicious code in @ensdomains/content-hash (npm)
file-type: ZIP Decompression Bomb DoS via [Content_Types].xml entry
@strapi/plugin-content-manager leaks data via relations via the Admin Panel
Qwik City has a CSRF Protection Bypass via Content-Type Header Validation
Mercurius: Incorrect Content-Type parsing can lead to CSRF attack
TinyMCE mXSS vulnerability in undo/redo, getContent API, resetContent API, and Autosave plugin
Hono CSRF middleware can be bypassed using crafted Content-Type header
Strapi may leak sensitive user information, user reset password, tokens via content-manager views
Malicious code in mitui-view-content (npm)
Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header
fastify vulnerable to denial of service via malicious Content-Type
Fastify: Incorrect Content-Type parsing can lead to CSRF attack
OpenClaw: Browser snapshot and screenshot routes could expose internal page content after navigation
Malicious code in content-tep (npm)
@grackle-ai/server has Missing Content-Security-Policy and X-Frame-Options Headers
Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries
Malicious code in @nc-tools/namp-cms-content-provider (npm)
Ghost vulnerable to arbitrary file read via symlinks in content import
Malicious code in ual-content-page (npm)
Malicious code in treeing-cur-content (npm)
Making all attributes on a content-type public without noticing it
Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content
Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
Malicious code in contentsdk-node (npm)
Fastify's Content-Type header tab character allows body validation bypass
Denial of Service and Content Injection in i18n-node-angular
Malicious code in braze-content-card-island (npm)
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
Electron's Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled
Joplin Vulnerable to Cross-site Scripting in Note Content
Malicious code in strapi-plugin-content-sync (npm)
Qwik City CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)
Malicious code in mydealer-content-service (npm)
Malicious code in idel2-content (npm)
Malicious code in volpino-italiano-content (npm)
Malicious code in adult-content-detection-aws (npm)
Malicious code in contentsource-connector (npm)
@hapi/content: Regular Expression Denial of Service (ReDoS) in HTTP header parsing
docusaurus-plugin-content-gists vulnerability exposes GitHub Personal Access Token
Malicious code in grouped-content (npm)
Malicious code in @content-platform/shared (npm)
User content sandbox can be confused into opening arbitrary documents
defuddle vulnerable to XSS via unescaped string interpolation in _findContentBySchemaText image tag
Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`
Malicious code in helix-contentsource-connector (npm)
next-mdx-remote affected by arbitrary code execution in React server-side rendering of untrusted MDX content
Malicious code in dibels8-content (npm)
Malicious code in react-content-loader-fork (npm)
Malicious code in typespublishercontenthash (npm)
markdown-it-toc Cross-site Scripting due to title of generated toc and contents of header not being escaped
Malicious code in @amber-team/social-content-ai-widget (npm)
Malicious code in fc-content (npm)
Malicious code in @goatapp/web-content-components (npm)
Malicious code in @nexthink/content-sharing (npm)
Malicious code in @nexthink/content-admin-list (npm)
Malicious code in mitui-comp-content (npm)
Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
Malicious code in @content-platform/fadam-module (npm)
Parse Server: File upload Content-Type override via extension mismatch
Malicious code in @codacontent/fetlife-assets (npm)
Malicious code in pp-react-content-loader (npm)
Malicious code in sdbao-content-report (npm)
Malicious code in sdbao-content-sems (npm)
Malicious code in client-aem-content-engine (npm)
i18next-http-middleware: HTTP response splitting and DoS via unsanitised Content-Language header
Malicious code in svg-content-validation (npm)
Malicious code in static-content-cannabis (npm)
Malicious code in rt-long-form-content (npm)