Known Vulnerabilities for GD Security Headers by Milan Petrovic
Listed below are 10 of the newest known vulnerabilities associated with "GD Security Headers" by "Milan Petrovic".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66746 json | Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arbitrar... | Not Provided | 2026-07-28 | 2026-07-29 |
| CVE-2026-63220 json | CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarde... | Not Provided | 2026-07-31 | 2026-07-31 |
| CVE-2026-57403 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Secur... | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-56425 json | The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization f... | Not Provided | 2026-06-22 | 2026-06-23 |
| CVE-2026-56398 json | Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the pictu... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-56244 json | Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient row-lev... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-54765 json | Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API... | Not Provided | 2026-07-06 | 2026-07-07 |
| CVE-2026-54477 json | The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks. | Not Provided | 2026-07-03 | 2026-07-06 |
| CVE-2026-54464 json | ### Impact If this library is used in tandem with the `permessage-deflate` extension, a WebSocket server or client can be ma... | Not Provided | 2026-07-17 | 2026-07-21 |
| CVE-2026-54303 json | n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger node... | Not Provided | 2026-06-23 | 2026-06-24 |