My CVEs
my vulnerability findings
CVE-2026-63080: Aptabase, cross-tenant SQL injection via Liquid templates
CVE-2026-63080
Aptabase's stats filters land raw in ClickHouse SQL: SQL injection and cross-tenant data leakage.
CVE-2026-54461: Habitica, regex injection and ReDoS in member search
CVE-2026-54461
A Habitica search field forgets to escape the input on the username: regex injection, enumeration and ReDoS.
CVE-2026-45231: DumbAssets, stored XSS in asset fields
CVE-2026-45231
DumbAssets stores asset fields raw and re-renders them via innerHTML: stored XSS.
CVE-2026-45230: DumbAssets, deleting any file on the server
CVE-2026-45230
Unauthenticated path traversal in DumbAssets' /api/delete-file: a single ../ is enough to wipe server.js.