Security: Part-DB/Part-DB-server
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Persistent Denial of Service via Uncaught Exception from Misleading File Extension in Avatar UploadGHSA-7rv3-rcxv-69ww published
Aug 13, 2025 by jbtronicsModerate -
Uploaded SVG files allow for stored XSS when opened in separate tabGHSA-whhf-g6wh-g35w published
May 24, 2025 by jbtronicsModerate -
HTML/XSS Injection Possibilities in Part-DB 1.0.0 and 1.0.1GHSA-9pmh-gmxx-rg2x published
Feb 26, 2023 by jbtronicsHigh