Security: walinejs/waline
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Stored XSS in the @waline/client UserList widget via an unescaped commenter link fieldGHSA-7w94-hxwm-gg99 published
Jul 5, 2026 by lizhemingHigh -
Stored XSS in @waline/client via the unsanitized markdown preview of a comment's raw body on editGHSA-crj3-q72p-ggqm published
Jul 2, 2026 by lizhemingCritical -
NoSQL injection in the login endpoint (POST /api/token): a non-string email is silently dropped by the MongoDB storage adapter, producing a match-all filter so the password is verified against the first-registered user (the administrator) — a partial authentication bypassGHSA-jf75-q64q-g65r published
Jun 12, 2026 by lizhemingModerate
Learn more about advisories related to walinejs/waline in the GitHub Advisory Database