Eclipse / Open Vsx
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-13323 | openvsx: Open VSX Registry: Supply chain attack via cross-site scripting | HIGH | 8.7 | Jul 1, 2026 |
| CVE-2026-4983 | Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without security h… | MEDIUM | 5.4 | Jun 23, 2026 |
| CVE-2025-6705 | A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the system’… | HIGH | 7.6 | Jun 27, 2025 |
| CVE-2025-1007 | Improper Authorization in /user/namespace/{namespace}/details | MEDIUM | 6.9 | Feb 19, 2025 |
Showing 1 to 4 of 4 CVEs