October 2026
1 advisoryJuly 2026
9 advisories- Critical
SQL Injection in Twenty CRM searchVector leads to Remote Code Execution
- Medium
Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account
- Medium
Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings
- Medium
Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails
- Medium
Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
- Medium
Uncontrolled resource consumption based on declared BMP dimensions
- Medium
RegexCheck causes Uncontrolled Resource Consumption
- High
[Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
- Medium
Stored XSS in Attachment Download Link via Dangerous MIME Types in PrivateBin