OsVault/npm/field
npm2 critical

field

54 known vulnerabilities · 2 critical · 7 high

CVE-2020-28269CRITICAL

Prototype Pollution in field

Published Dec 10, 2021
GHSA-855c-r2vq-c292

Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS

Published Apr 16, 2026
CVE-2023-30843HIGH

Hidden fields can be leaked on readable collections in Payload

Published Apr 26, 2023
GHSA-c276-fj82-f2pq

ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions

Published Apr 16, 2026
CVE-2026-30962

Parse Server has a protected fields bypass via logical query operators

Published Mar 11, 2026
CVE-2026-35442HIGH
Risk: 47.05/100

Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries

Published Apr 4, 2026
CVE-2023-31133HIGH

Ghost vulnerable to information disclosure of private API fields

Published May 3, 2023
GHSA-mvv8-v4jj-g47j

Directus: Sensitive fields exposed in revision history

Published Apr 4, 2026
CVE-2021-41182MEDIUM

XSS in the `altField` option of the Datepicker widget in jquery-ui

Published Oct 26, 2021
CVE-2026-32234

Parse Server has a SQL injection via query field name when using PostgreSQL

Published Mar 12, 2026
GHSA-4hxc-9384-m385

h3: SSE Event Injection via Unsanitized Carriage Return (`\r`) in EventStream Data and Comment Fields (Bypass of CVE Fix)

Published Mar 20, 2026
CVE-2026-32742

Parse Server session creation endpoint allows overwriting server-generated session fields

Published Mar 17, 2026
CVE-2023-48218MEDIUM

Bypass of field access control in strapi-plugin-protected-populate

Published Nov 20, 2023
CVE-2026-31856

Parse Server vulnerable to SQL injection via `Increment` operation on nested object field in PostgreSQL

Published Mar 11, 2026
CVE-2022-39322CRITICAL

Field-level access-control bypass for multiselect field

Published Oct 18, 2022
CVE-2022-31112HIGH

Protected fields exposed via LiveQuery

Published Jul 6, 2022
CVE-2025-30352

Directus `search` query parameter allows enumeration of non permitted fields

Published Mar 26, 2025
MAL-2022-5432

Malicious code in pp-amount-field (npm)

Published Jun 20, 2022
CVE-2026-33128

h3 has a Server-Sent Events Injection via Unsanitized Newlines in Event Stream Fields

Published Mar 18, 2026
CVE-2023-37263MEDIUM

Strapi's field level permissions not being respected in relationship title

Published Sep 13, 2023
GHSA-g4v2-qx3q-4p64

Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`

Published Apr 8, 2026
CVE-2026-24737

jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript Execution

Published Feb 2, 2026
CVE-2022-32214MEDIUM

llhttp allows HTTP Request Smuggling via Improper Delimiting of Header Fields

Published Jul 15, 2022
GHSA-97v6-998m-fp4g

ApostropheCMS: Stored XSS via CSS Custom Property Injection in @apostrophecms/color-field Escaping Style Tag Context

Published Apr 16, 2026
CVE-2026-33539

Parse Server has SQL Injection through aggregate and distinct field names in PostgreSQL adapter

Published Mar 24, 2026
CVE-2023-34235HIGH

Leaking sensitive user information still possible by filtering on private with prefix fields

Published Jul 25, 2023
CVE-2026-32098

Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause

Published Mar 12, 2026
CVE-2026-33527

Parse Server's Session Update endpoint allows overwriting server-generated session fields

Published Mar 24, 2026
CVE-2026-33429

Parse Server has a protected field change detection oracle via LiveQuery watch parameter

Published Mar 20, 2026
CVE-2026-34363MEDIUM
Risk: 26.51/100

LiveQuery protected field leak via shared mutable state across concurrent subscribers

Published Mar 30, 2026
CVE-2026-31840

Parse Server: SQL injection via dot-notation field name in PostgreSQL

Published Mar 10, 2026
CVE-2026-35038
Risk: 0.03/100

Signal K Server: Arbitrary Prototype Read via `from` Field Bypass

Published Apr 3, 2026
MAL-2024-1066

Malicious code in dropdownformfield (npm)

Published Mar 9, 2024
CVE-2026-29085

Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()

Published Mar 4, 2026
CVE-2026-33163

Parse Server leaks protected fields via LiveQuery afterEvent trigger

Published Mar 18, 2026
CVE-2019-13127MEDIUM

mxGraph vulnerable to cross-site scripting in color field

Published May 24, 2022
CVE-2025-64530

@apollo/composition has Improper Enforcement of Access Control on Interface Types and Fields

Published Nov 14, 2025
CVE-2023-22894MEDIUM

Strapi leaking sensitive user information by filtering on private fields

Published Apr 19, 2023
CVE-2026-34595MEDIUM
Risk: 21.51/100

Parse Server has a LiveQuery protected-field guard bypass via array-like logical operator value

Published Apr 1, 2026
CVE-2021-32624HIGH

Private Field data leak

Published May 27, 2021
CVE-2023-25572MEDIUM

Cross-Site-Scripting attack on `<RichTextField>`

Published Feb 14, 2023
CVE-2026-33894

Forge has signature forgery in RSA-PKCS due to ASN.1 extra field

Published Mar 26, 2026
CVE-2026-28359

NocoDB Vulnerable to Stored Cross-site Scripting via Rich Text Field

Published Mar 2, 2026
MAL-2022-317

Malicious code in @harrysforge/input-field (npm)

Published Jun 20, 2022
MAL-2026-108

Malicious code in @nestor_hexom/garfield (npm)

Published Jan 7, 2026
MAL-2026-114

Malicious code in garfield777 (npm)

Published Jan 7, 2026
MAL-2022-5172

Malicious code in p2p-amount-field (npm)

Published Jun 20, 2022
MAL-2022-5631

Malicious code in react-address-entry-field (npm)

Published Jun 20, 2022
GHSA-ppwq-6v66-5m6j

OpenClaw Exposes Credentials Embedded in baseUrl Fields via config.get and channels.status

Published Mar 26, 2026
MAL-2026-113

Malicious code in garfield000 (npm)

Published Jan 7, 2026
CVE-2026-34574MEDIUM
Risk: 27.01/100

Parse Server has a session field immutability bypass via falsy-value guard

Published Apr 1, 2026
CVE-2023-39345HIGH

Unauthorized Access to Private Fields in User Registration API

Published Nov 3, 2023
CVE-2026-31872

Parse Server has a protected fields bypass via dot-notation in query and sort

Published Mar 11, 2026
MAL-2026-109

Malicious code in @nestor_hexom/garfield1 (npm)

Published Jan 7, 2026
Check your entire dependency tree at onceRun dependency scan →