My CVEs

my vulnerability findings

11/07/2026 High

CVE-2026-63080: Aptabase, cross-tenant SQL injection via Liquid templates

CVE-2026-63080

Aptabase's stats filters land raw in ClickHouse SQL: SQL injection and cross-tenant data leakage.

CVESQL InjectionAptabaseClickHouseMulti-tenant
04/06/2026 Medium

CVE-2026-54461: Habitica, regex injection and ReDoS in member search

CVE-2026-54461

A Habitica search field forgets to escape the input on the username: regex injection, enumeration and ReDoS.

CVEReDoSRegex InjectionHabiticaNode.js
18/05/2026 Medium

CVE-2026-45231: DumbAssets, stored XSS in asset fields

CVE-2026-45231

DumbAssets stores asset fields raw and re-renders them via innerHTML: stored XSS.

CVEXSSDumbAssetsWeb
18/05/2026 Critical

CVE-2026-45230: DumbAssets, deleting any file on the server

CVE-2026-45230

Unauthenticated path traversal in DumbAssets' /api/delete-file: a single ../ is enough to wipe server.js.

CVEPath TraversalDumbAssetsNode.js