Sicherheit
Security
All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.
| CVE / GHSA | Item | Vertical | Severity | Date |
|---|---|---|---|---|
| CVE-2026-42231 Source A vulnerability in n8n's XML processing allows authenticated users to manipulate JavaScript object structures through crafted XML data and thereby execute arbitrary code on the server. |
n8n | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-33660 Source A vulnerability in the n8n workflow software allows authenticated users to read local files and execute malicious code through the Merge node due to insufficient restrictions on SQL statements. |
n8n | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-42232 Source A vulnerability in the n8n workflow software allows authenticated users to execute malicious code by manipulating JavaScript prototypes through the XML node component. |
n8n | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-44790 Source A vulnerability in the n8n workflow software allows authenticated users to read arbitrary files from the server and potentially achieve full system compromise through the Git functionality. |
n8n | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-44789 Source A vulnerability in the n8n workflow software allows authenticated users to execute malicious code and compromise the entire system through an unvalidated parameter in the HTTP Request node. |
n8n | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-45732 Source A security flaw in n8n allows users with read-only access to shared OAuth credentials to replace them with their own tokens, enabling them to control workflows and potentially steal data. |
n8n | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-44792 Source A vulnerability in n8n workflow software allows SQL injection attacks when an attacker plants malicious files in a connected Git repository and an administrator imports them through the Source Control feature. |
n8n | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-44791 Source A security vulnerability in the n8n workflow software allows authenticated users with workflow permissions to bypass a previous security fix in the XML node and execute malicious code on the server. |
n8n | Self-hosted apps | Critical | 07.06.2026 |
| GHSA-24m5-7vjx-9x37 Source Multiple integrations in Homepage can unintentionally access external APIs and retrieve their responses, potentially exposing sensitive data like passwords or API keys to unauthorized parties. |
Homepage | Self-hosted apps | Critical | 07.06.2026 |
| GHSA-c4qv-fm8g-wm67 Source A vulnerability in the Homepage software allows unauthenticated users to check whether arbitrary files and directories exist on the server by exploiting different responses from an API endpoint. |
Homepage | Self-hosted apps | Medium | 07.06.2026 |
| GHSA-rg3r-jprv-xq38 Source A vulnerability in the Homepage software allows attackers to perform path traversal attacks on backend servers through an unsanitized parameter, potentially forwarding stored authentication credentials to unintended targets. |
Homepage | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2023-51442 Source A vulnerability in Navidrome music server software allows attackers to log in as any user without knowing their password. This only works on freshly installed servers that have never been restarted, because a programming bug uses a predictable security key instead of generating a random one. |
Navidrome | Self-hosted apps | High | 07.06.2026 |
| CVE-2024-32963 Source Navidrome, a music streaming software, has a parameter validation vulnerability that allows attackers to manipulate HTTP request parameters and impersonate other users, including administrators. |
Navidrome | Self-hosted apps | High | 07.06.2026 |
| CVE-2024-47062 Source Navidrome, a music streaming software, has critical security flaws: URL parameters are unsafely inserted into SQL queries, allowing attackers to guess passwords, extract arbitrary database data, or log in with incorrect usernames. |
Navidrome | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2024-56362 Source Navidrome stores a critical authentication secret unencrypted in the database file, allowing attackers with file access to create forged user tokens and impersonate any user including administrators. |
Navidrome | Self-hosted apps | High | 07.06.2026 |
| CVE-2025-27112 Source A vulnerability in Navidrome allows attackers to bypass authentication by using a non-existent username with an empty password hash. This grants unauthorized read-only access to server data such as playlists. |
Navidrome | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2025-48948 Source A permission flaw in Navidrome music server software allows regular users to access administrator-only transcoding configuration functions despite lacking administrative privileges. |
Navidrome | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2025-48949 Source A critical SQL injection vulnerability in the Navidrome music server software allows attackers to execute malicious database commands through the 'role' parameter of the API, potentially stealing or manipulating user data. |
Navidrome | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-25579 Source A vulnerability in the Navidrome music server software allows authenticated users to crash the server by sending excessively large image size parameters, causing uncontrolled memory consumption or disk space exhaustion. |
Navidrome | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-25578 Source A vulnerability in the Navidrome music server software allows attackers to inject malicious code through comment metadata in music files, which executes when viewing song information and can steal user credentials. |
Navidrome | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2020-5256 Source BookStack software allowed users to upload malicious PHP files through image upload functions, enabling them to execute arbitrary code on the server. |
BookStack | Self-hosted apps | High | 07.06.2026 |
| CVE-2020-11055 Source BookStack users with comment permissions could inject malicious HTML code and JavaScript into comments, which would then execute on other users' browsers. This enabled cross-site scripting attacks against other users of the platform. |
BookStack | Self-hosted apps | Medium | 07.06.2026 |
| GHSA-c32x-84w6-5mxq Source BookStack exposes names of restricted books to unauthorized users when viewing shelves in list view, potentially revealing sensitive book titles to those without proper permissions. |
BookStack | Self-hosted apps | Low | 07.06.2026 |
| CVE-2020-26211 Source BookStack users with page editing permissions could inject malicious JavaScript code through links or meta tags that executes when clicked or silently redirects users to other locations. |
BookStack | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2020-26210 Source In the BookStack wiki software, users with page editing permissions can add malicious JavaScript links as attachments that execute when clicked by other users viewing the page. |
BookStack | Self-hosted apps | Low | 07.06.2026 |
| CVE-2020-26260 Source A vulnerability in BookStack allows users with page editing permissions to make server-side requests and access files in BookStack storage through manipulated image URLs. |
BookStack | Self-hosted apps | Medium | 07.06.2026 |
| GHSA-9g92-rjqm-pjj5 Source BookStack software accidentally displays names and preview content of supposedly hidden pages when all pages within a visible chapter were set to be invisible. |
BookStack | Self-hosted apps | Medium | 07.06.2026 |
| GHSA-7qjg-w49c-5346 Source BookStack software has a vulnerability where users can view content from pages they shouldn't have access to through the plaintext export feature, bypassing permission restrictions. |
BookStack | Self-hosted apps | High | 07.06.2026 |
| GHSA-mgj7-rfx8-vhpr Source Audiobookshelf contains security vulnerabilities that allow users with update permissions to read or delete arbitrary files and send HTTP requests to internal servers. |
Audiobookshelf | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2023-51665 Source Audiobookshelf software version 2.6.0 contains a vulnerability that allows attackers without authentication to make the server send requests to arbitrary internal or external systems. |
Audiobookshelf | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2023-51697 Source Audiobookshelf version 2.6.0 contains a vulnerability that allows attackers without authentication to make the server send requests to arbitrary internal or external addresses. |
Audiobookshelf | Self-hosted apps | Low | 07.06.2026 |
| CVE-2024-35236 Source A security vulnerability in Audiobookshelf software allows malicious e-books to execute JavaScript code, which can lead to complete server takeover when viewed by privileged users. |
Audiobookshelf | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2024-43797 Source A vulnerability in Audiobookshelf allows regular users without admin privileges to create libraries and write to arbitrary directories on the system due to a missing permission check. |
Audiobookshelf | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2025-25205 Source A vulnerability in Audiobookshelf software allows attackers to bypass authentication using special URL parameters, leading to data leaks and complete server crashes. |
Audiobookshelf | Self-hosted apps | High | 07.06.2026 |
| CVE-2025-46338 Source A vulnerability in Audiobookshelf software allows cross-site scripting attacks through improper input handling in the upload endpoint, enabling attackers to inject malicious code into error messages and execute it in browsers. |
Audiobookshelf | Self-hosted apps | Medium | 07.06.2026 |
| GHSA-xj8h-wrw2-g829 Source A vulnerability in Audiobookshelf allows authenticated users with upload permissions to check the existence of arbitrary files on the server, even outside the permitted library folders. |
Audiobookshelf | Self-hosted apps | Medium | 07.06.2026 |
| GHSA-xjqw-8829-qmm6 Source A vulnerability in Audiobookshelf allows authenticated users with upload permissions to check for the existence of arbitrary files on the server through path manipulation, enabling filesystem reconnaissance. |
Audiobookshelf | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2025-57800 Source A security vulnerability in Audiobookshelf software allows attackers to steal user tokens by sending malicious login links that trick the application into redirecting authentication tokens to attacker-controlled servers. |
Audiobookshelf | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-27963 Source A vulnerability in the Audiobookshelf web application allows attackers with library access to inject malicious JavaScript code into book titles that executes when other users hover their mouse over the book cover. |
Audiobookshelf | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-27974 Source A vulnerability in the Audiobookshelf mobile app allows attackers with library access to inject malicious code through manipulated titles or chapter names that executes when content is played, potentially stealing user data. |
Audiobookshelf | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-27973 Source A vulnerability in the Audiobookshelf mobile app allows attackers with library access to inject malicious code into audiobook metadata that executes in other users' browsers, potentially stealing their session data and accessing device functions. |
Audiobookshelf | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-42883 Source A security vulnerability in Audiobookshelf allows authenticated users to download files from libraries they shouldn't have access to by sending crafted download requests with foreign file IDs. |
Audiobookshelf | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-42884 Source A security vulnerability in Audiobookshelf software allows authenticated users to view collections and book metadata from libraries they should not have access to, because the API endpoints fail to properly check library access permissions. |
Audiobookshelf | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-42885 Source A vulnerability in Audiobookshelf allows authenticated users with upload permissions to check file existence outside their assigned library folders due to flawed string validation that fails to properly exclude sibling directories with similar names. |
Audiobookshelf | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-42886 Source A vulnerability in Audiobookshelf software allows administrators to upload specially crafted ZIP files that consume excessive memory when decompressed, potentially crashing the server through memory exhaustion. |
Audiobookshelf | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-42887 Source A security vulnerability in Audiobookshelf software allows administrators to inject malicious code into the login page that executes for all users and can capture their login credentials. |
Audiobookshelf | Self-hosted apps | Medium | 07.06.2026 |
| GHSA-qr9h-3q76-7gj8 Source A vulnerability in Audiobookshelf allows signed-in users to inject malicious code into session data that executes when administrators visit the session overview, enabling attackers to gain admin privileges. |
Audiobookshelf | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-42888 Source A path traversal vulnerability in Audiobookshelf software allows attackers to access files outside intended library folders during podcast creation, potentially enabling them to read, write, or delete unauthorized files. |
Audiobookshelf | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2021-29456 Source Authelia authentication software fails to properly validate redirect URLs during logout, allowing attackers to redirect users to arbitrary malicious websites for phishing attacks. |
Authelia | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2021-32637 Source A security vulnerability in Authelia allows attackers to bypass authentication by sending malformed HTTP requests to nginx servers using the ngx_http_auth_request_module. |
Authelia | Self-hosted apps | High | 07.06.2026 |