Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/@saltcorn/server — 4 CVEs · VulnScope
pkg:npm/
@saltcorn/server
4 total CVEs
CRITICAL
1
HIGH
1
MEDIUM
1
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.9
CVE-2026-41478
Saltcorn: SQL Injection via Unparameterized Sync Endpoints (maxLoadedId)
from 0, < 1.4.6
HIGH
8.2
CVE-2026-40163
Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read
from 0, < 1.4.5
MEDIUM
6.5
CVE-2024-47818
Saltcorn Server allows logged-in users to delete arbitrary files because of a path traversal vulnerability
from 0, < 1.0.0-beta.16
—
Saltcorn: Open Redirect in `POST /auth/login` due to incomplete `is_relative_url` validation (backslash bypass)
from 0, < 1.4.6
CVE-2026-42259