CVE-2026-47716
- EPSS 0.15%
- Veröffentlicht 26.05.2026 16:23:34
- Zuletzt bearbeitet 26.05.2026 19:37:00
Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list view authorizes access through the project in the URL, but applies the requested bulk action to the submitted issue IDs without also requiring those is...
CVE-2026-47715
- EPSS 0.15%
- Veröffentlicht 26.05.2026 16:22:23
- Zuletzt bearbeitet 26.05.2026 19:37:00
Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier from the URL and, in affected versions, look up that event without also requiring it to belong to the issue in the URL. This is a...
CVE-2026-47728
- EPSS 0.18%
- Veröffentlicht 26.05.2026 16:16:10
- Zuletzt bearbeitet 26.05.2026 19:37:00
Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID without scoping that lookup to the project that owned the uploaded metadata. An authenticated user with access to one project could ...
CVE-2026-44502
- EPSS 0.29%
- Veröffentlicht 26.05.2026 16:13:32
- Zuletzt bearbeitet 26.05.2026 19:37:00
Bugsink is a self-hosted error tracking tool. Prior to 2.1.3, Bugsink’s webhook URL validation could be (partially) bypassed because of a mismatch in URL parsing. The original validation logic parsed webhook URLs with Python’s urllib.parse.urlparse, ...
CVE-2026-40162
- EPSS 0.3%
- Veröffentlicht 10.04.2026 17:02:58
- Zuletzt bearbeitet 15.04.2026 19:05:54
Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugsink 2.1.0 in the artifact bundle assembly flow. A user with a valid authentication token could cause the application to write atta...
CVE-2026-27614
- EPSS 0.29%
- Veröffentlicht 25.02.2026 03:16:05
- Zuletzt bearbeitet 27.02.2026 19:06:26
Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit events to a Bugsink project can store arbitrary JavaScript in an event. The payload executes only if a user explicitly views the aff...