Known Vulnerabilities for JSON-RPC API by Leantime
Listed below are 10 of the newest known vulnerabilities associated with "JSON-RPC API" by "Leantime".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-77070 json | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggr... | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-77067 json | The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address val... | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-76647 json | Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatcher in app/... | Not Provided | 2026-08-19 | 2026-08-19 |
| CVE-2026-75860 json | The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its action... | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-75483 json | powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segm... | Not Provided | 2026-08-17 | 2026-08-20 |
| CVE-2026-75482 json | SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-74875 json | openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allo... | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-74244 json | A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to f... | Not Provided | 2026-08-14 | 2026-08-17 |
| CVE-2026-74240 json | A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) auth... | Not Provided | 2026-08-14 | 2026-08-20 |
| CVE-2026-74039 json | Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with ... | Not Provided | 2026-08-18 | 2026-08-18 |