content
99 known vulnerabilities · 0 critical · 7 high
Strapi Upload Plugin MIME Validation Bypass via Content API
Qwik City has a CSRF Protection Bypass via Content-Type Header Validation
Hono allows bypass of CSRF Middleware by a request without Content-Type header.
Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation
Malicious code in @ensdomains/content-hash (npm)
file-type: ZIP Decompression Bomb DoS via [Content_Types].xml entry
@strapi/plugin-content-manager leaks data via relations via the Admin Panel
Hono CSRF middleware can be bypassed using crafted Content-Type header
Malicious code in mitui-view-content (npm)
Mercurius: Incorrect Content-Type parsing can lead to CSRF attack
Fastify: Incorrect Content-Type parsing can lead to CSRF attack
OpenClaw: Browser snapshot and screenshot routes could expose internal page content after navigation
Malicious code in content-tep (npm)
Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries
Malicious code in @nc-tools/namp-cms-content-provider (npm)
Ghost vulnerable to arbitrary file read via symlinks in content import
Malicious code in ual-content-page (npm)
Fastify has a Body Schema Validation Bypass via Leading Space in Content-Type Header
Malicious code in treeing-cur-content (npm)
@grackle-ai/server has Missing Content-Security-Policy and X-Frame-Options Headers
fastify vulnerable to denial of service via malicious Content-Type
Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content
Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
Making all attributes on a content-type public without noticing it
Malicious code in contentsdk-node (npm)
Denial of Service and Content Injection in i18n-node-angular
Malicious code in braze-content-card-island (npm)
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
Fastify's Content-Type header tab character allows body validation bypass
Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
Electron's Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled
Joplin Vulnerable to Cross-site Scripting in Note Content
TinyMCE mXSS vulnerability in undo/redo, getContent API, resetContent API, and Autosave plugin
Malicious code in strapi-plugin-content-sync (npm)
Qwik City CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)
Strapi Vulnerable to SQL Injection in Content Type Builder
Malicious code in idel2-content (npm)
Malicious code in adult-content-detection-aws (npm)
Malicious code in @ethlete/contentful (npm)
Malicious code in contentsource-connector (npm)
@tdurieux/anonymous_github Vulnerable to XSS via Unsanitized GitHub Repository Content Rendering in Anonymous GitHub Origin
Malicious code in grouped-content (npm)
Malicious code in @content-platform/shared (npm)
Malicious code in mydealer-content-service (npm)
User content sandbox can be confused into opening arbitrary documents
defuddle vulnerable to XSS via unescaped string interpolation in _findContentBySchemaText image tag
Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`
Axios: HTTP adapter streamed responses bypass maxContentLength
next-mdx-remote affected by arbitrary code execution in React server-side rendering of untrusted MDX content
Malicious code in dibels8-content (npm)
Malicious code in react-content-loader-fork (npm)
Malicious code in typespublishercontenthash (npm)
Malicious code in @amber-team/social-content-ai-widget (npm)
markdown-it-toc Cross-site Scripting due to title of generated toc and contents of header not being escaped
Malicious code in fc-content (npm)
Malicious code in @goatapp/web-content-components (npm)
Malicious code in @nexthink/content-sharing (npm)
Malicious code in @databus-service-ui/scroll-up-content (npm)
Malicious code in @nexthink/content-admin-list (npm)
Malicious code in claude-content-writer (npm)
Malicious code in @content-platform/fadam-module (npm)
Malicious code in @codacontent/fetlife-assets (npm)
DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes
Malicious code in pp-react-content-loader (npm)
DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content
Malicious code in sdbao-content-report (npm)
Malicious code in sdbao-content-sems (npm)
@webiny/react-rich-text-renderer vulnerable to insecure rendering of rich text content
open-websearch has SSRF in `fetchWebContent` MCP tool: bracketed IPv6 literals and non-resolving hostname check bypass `isPrivateOrLocalHostname`
Malicious code in client-aem-content-engine (npm)
i18next-http-middleware: HTTP response splitting and DoS via unsanitised Content-Language header
DOMPurify XSS via selectedcontent re-clone
Malicious code in svg-content-validation (npm)
@hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters
Malicious code in getd-content-management (npm)
Malicious code in static-content-cannabis (npm)
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
Strapi may leak sensitive user information, user reset password, tokens via content-manager views
Malicious code in mitui-comp-content (npm)
@hapi/content: Regular Expression Denial of Service (ReDoS) in HTTP header parsing
Malicious code in rt-long-form-content (npm)
Parse Server: File upload Content-Type override via extension mismatch
Cross-site scripting via <NoScript> slot content in Nuxt's head components
Malicious code in volpino-italiano-content (npm)
@cyntler/react-doc-viewer's TXTRenderer fails to sanitize file content and explicitly casts raw data as a ReactNode
docusaurus-plugin-content-gists vulnerability exposes GitHub Personal Access Token
Malicious code in macos-contentprovider-optimizingassets (npm)
Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
Malicious code in helix-contentsource-connector (npm)