VDB
Sign up

package

npm/@saltcorn/server

pkg:npm/%40saltcorn/server

MEDIUM4.4npm
GHSA-277h-px4m-62q8

@saltcorn/server arbitrary file zip read and download when downloading auto backups

Modified: 10/3/2024

HIGH7.2npm
GHSA-78p3-fwcq-62c2

@saltcorn/server Remote Code Execution (RCE) / SQL injection via prototype pollution by manipulating `lang` and `defstring` parameters when setting localizer strings

Modified: 10/3/2024

MEDIUM4.9npm
GHSA-cfqx-f43m-vfh7

@saltcorn/server arbitrary file and directory listing when accessing build mobile app results

Modified: 10/3/2024

CRITICAL9.6npm
GHSA-cr3w-cw5w-h3fj

Saltcorn's Reflected XSS and Command Injection vulnerabilities can be chained for 1-click-RCE

Modified: 2/3/2026

MEDIUM6.1npm
GHSA-pf56-h9qf-rxq4

Saltcorn Server Stored Cross-Site Scripting (XSS) in event logs page

Modified: 10/7/2024