Known Vulnerabilities for Json-patch by Json-patch Project
Listed below are 2 of the newest known vulnerabilities associated with "Json-patch" by "Json-patch Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-63751 json | SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allows au... | Not Provided | 2026-07-20 | 2026-07-20 |
| CVE-2026-55570 json | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name,... | Not Provided | 2026-06-24 | 2026-06-25 |
| CVE-2026-54066 json | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Traversal ... | Not Provided | 2026-06-24 | 2026-06-25 |
| CVE-2026-52840 json | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `applica... | Not Provided | 2026-07-14 | 2026-07-15 |
| CVE-2026-49279 json | WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEval... | Not Provided | 2026-07-15 | 2026-07-18 |
| CVE-2026-48824 json | Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-4... | Not Provided | 2026-07-20 | 2026-07-20 |
| CVE-2026-48089 json | DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instance wit... | Not Provided | 2026-06-19 | 2026-06-22 |
| CVE-2026-47900 json | Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaScript payload in the "name... | Not Provided | 2026-06-09 | 2026-06-09 |
| CVE-2026-47411 json | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authoriz... | Not Provided | 2026-07-21 | 2026-07-21 |
| CVE-2026-47356 json | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file sc... | Not Provided | 2026-05-19 | 2026-05-19 |