Security: Syslifters/sysreptor
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Unauthorized file disclosure by broken access control in writable shared notesGHSA-x3m3-v8pv-442r published
Aug 20, 2026 by aronmolnarModerate -
Session fixation in password protected shared notesGHSA-wgx3-84xg-q93j published
Aug 20, 2026 by aronmolnarLow -
Host header injection might allow account takeoverGHSA-9x2r-5pff-8w6c published
Jul 21, 2026 by aronmolnarHigh -
Authenticated RCE by insecure image processingGHSA-wmf3-gv8j-7qp7 published
Jul 30, 2026 by aronmolnarHigh -
Anonymous note-share link discloses project member identities and non-shared note activityGHSA-926c-j47w-8f9c published
Jul 15, 2026 by MWedlLow -
Privilege Escalation from User Admin to SuperuserGHSA-6x8f-v3cf-cvr3 published
May 6, 2026 by aronmolnarLow -
Read-write access to personal notes by sharing-link creation with no authorization in SysReptor ProfessionalGHSA-pcpr-q2qj-3v43 published
Apr 22, 2026 by MWedlModerate -
Authenticated Stored Cross-Site Scripting (XSS)GHSA-64vw-v5c4-mgvm published
Dec 4, 2025 by aronmolnarHigh -
Privilege Escalation by Authenticated UsersGHSA-r6hm-59cq-gjg6 published
Sep 26, 2025 by aronmolnarHigh -
Cross-Site Websocket Hijacking in SysReptorGHSA-2vfc-3h43-vghh published
May 21, 2024 by aronmolnarModerate