CRITICAL10.0CVE-2026-44523Note Mark has a JWT Secret Weakness that allows Full Account Takeover via Token Forgery in github.com/enchant97/note-mark/backend from 0, < 0.0.0-20260501152247-18b587758667
CRITICAL10.0CVE-2026-44523Note Mark has a JWT Secret Weakness that allows Full Account Takeover via Token Forgery in github.com/enchant97/note-mark/backend from 0, < 0.0.0-20260501152247-18b587758667
CRITICAL9.4Note Mark: OIDC-registered users authenticated by submitting password "null" in github.com/enchant97/note-mark/backend
from 0, < 0.0.0-20260417132909-dea5530cc989
CRITICAL9.4Note Mark: OIDC-registered users authenticated by submitting password "null" in github.com/enchant97/note-mark/backend
from 0, < 0.0.0-20260417132909-dea5530cc989
HIGH8.7Note Mark has Stored XSS via Unrestricted Asset Upload in github.com/enchant97/note-mark/backend
from 0, < 0.0.0-20260411145018-6bb62842ccb9
HIGH8.7Note Mark has Stored XSS via Unrestricted Asset Upload in github.com/enchant97/note-mark/backend
from 0, < 0.0.0-20260411145018-6bb62842ccb9
MEDIUM5.9Note Mark has Broken Access Control on Asset Download in github.com/enchant97/note-mark/backend
from 0, < 0.0.0-20260411145023-6593898855ad
MEDIUM5.9Note Mark has Broken Access Control on Asset Download in github.com/enchant97/note-mark/backend
from 0, < 0.0.0-20260411145023-6593898855ad
MEDIUM5.3Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books
from 0, < 0.0.0-20260601210758-9c9b72740f22
MEDIUM5.3Note Mark: Unauthenticated read of notes and assets in soft-deleted public books in github.com/enchant97/note-mark/backend
from 0, < 0.0.0-20260417132843-d1bf845a2a2d
MEDIUM5.3Note Mark: Unauthenticated read of notes and assets in soft-deleted public books in github.com/enchant97/note-mark/backend
from 0, < 0.0.0-20260417132843-d1bf845a2a2d
LOW3.7Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel in github.com/enchant97/note-mark/backend
from 0, < 0.19.2-0.20260411145025-cf4c6f6acf70
LOW3.7Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel in github.com/enchant97/note-mark/backend
from 0
—Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)
from 0, < 0.0.0-20260601210719-67b7de04308a
—Note Mark: Arbitrary File Write via Path Traversal in Asset Names Leads to Remote Code Execution in github.com/enchant97/note-mark/backend
from 0, < 0.0.0-20260501152243-db3f72bff780
—Note Mark: Arbitrary File Write via Path Traversal in Asset Names Leads to Remote Code Execution in github.com/enchant97/note-mark/backend
from 0, < 0.0.0-20260501152243-db3f72bff780