Known Vulnerabilities for Website by Yarnpkg
Listed below are 1 of the newest known vulnerabilities associated with "Website" by "Yarnpkg".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-64622 json | Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/secre... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-62387 json | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS c... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-61736 json | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combi... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-59153 json | Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media f... | Not Provided | 2026-07-07 | 2026-07-08 |
| CVE-2026-58656 json | Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Control-A... | Not Provided | 2026-07-08 | 2026-07-08 |
| CVE-2026-58482 json | Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox`... | Not Provided | 2026-07-20 | 2026-07-20 |
| CVE-2026-58077 json | The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request m... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-57619 json | Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions. | Not Provided | 2026-06-25 | 2026-06-25 |
| CVE-2026-56028 json | Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4.9 versions. | Not Provided | 2026-06-26 | 2026-06-29 |
| CVE-2026-55439 json | Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download endpoint... | Not Provided | 2026-06-25 | 2026-06-25 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Yarnpkg | Website | 2018-06-05 |