Known Vulnerabilities for JSON-RPC API by Leantime
Listed below are 10 of the newest known vulnerabilities associated with "JSON-RPC API" by "Leantime".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-89257 json | AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.ph... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-89254 json | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Cu... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-89253 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in t... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-89248 json | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/Web... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-89247 json | WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-89242 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in t... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-89212 json | A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted ... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-89148 json | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php. Because... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-89066 json | Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 mi... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-88873 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in vi... | Not Provided | 2026-09-10 | 2026-09-10 |