The catalog
Browse GHSA Reproductions
85 verified reproductions
Popular records
Top viewed reproduction records
Frequently opened evidence pages with direct links to runnable proof and permanent REPRO IDs.
REPRO-2026-00356 WordPress Core unauthenticated path traversal in get_page_template() page-template resolution leading to conditional RCE REPRO-2026-00354 GitLab CE/EE unauthenticated path traversal in Repository Commits API leads to arbitrary file read REPRO-2026-00341 JFrog Artifactory critical unauthenticated authentication bypass leading to administrative takeover REPRO-2026-00357 Next.js next/og ImageResponse RCE via Satori improper SVG escaping (critical) REPRO-2026-00337 Keycloak reset-credentials flow: unauthenticated account takeover (CWE-640) REPRO-2026-00355 ArangoDB full-chain: unauthenticated %5f URL auth bypass (GHSA-rrgq-978q-36mq) + client-controlled isSystem task escalation (GHSA-rvhw-4hpw-9vrx) -> root-context file write -> host RCE
85 reproductions
Clear filters Active GHSA
REPRO-2026-00114 published
D-Tale Remote Code Execution via Custom Filter Input
CVE-2026-27194 critical Security pip
dtale
11m 53s Feb 20, 2026
REPRO-2026-00113 published
Feathers OAuth Authorization Header Leak to Third-Party
CVE-2026-27192 high Security npm
@feathersjs/authentication-oauth
7m 45s Feb 20, 2026
REPRO-2026-00112 published
Statamic CMS Stored XSS via Markdown Fieldtype
CVE-2026-27197 critical Security composer
statamic/cms
7m 48s Feb 20, 2026
REPRO-2026-00111 published
Formwork CMS Improper Privilege Management in User Creation
CVE-2026-27198 high Security composer
getformwork/formwork
12m 42s Feb 20, 2026
REPRO-2026-00110 published
Deno Command Injection via Incomplete Metacharacter Blocklist
CVE-2026-27190 high Security rust
deno
10m 5s Feb 20, 2026
REPRO-2026-00109 published
Feathers OAuth Open Redirect Account Takeover
CVE-2026-27191 medium Security npm
@feathersjs/authentication-oauth
12m 54s Feb 20, 2026
REPRO-2026-00108 published
Zumba JSON Serializer PHP Object Injection
CVE-2026-27206 high Security composer
zumba/json-serializer
11m 26s Feb 20, 2026
REPRO-2026-00107 published
Swiper Prototype Pollution
CVE-2026-27212 high Security npm
swiper
10m 21s Feb 20, 2026
REPRO-2026-00106 published
Dagu Unauthenticated RCE via Inline DAG Spec
GHSA-6qr9-g2xw-cw92 critical Security go
github.com/dagu-org/dagu
18m 38s Feb 20, 2026
REPRO-2026-00105 published
Fabric.js: Stored XSS via SVG Export
CVE-2026-27013 high Security npm
fabric
16m 24s Feb 19, 2026
REPRO-2026-00104 published
systeminformation: Command Injection via WiFi Interface Parameter
CVE-2026-26280 high Security npm
systeminformation
19m 36s Feb 19, 2026
REPRO-2026-00103 published
jsPDF: PDF Object Injection via Unsanitized addJS Input
CVE-2026-25755 high Security npm
jspdf
14m 30s Feb 19, 2026
REPRO-2026-00102 published
jsPDF: PDF Injection in AcroForm RadioButton allows JS Execution
CVE-2026-25940 high Security npm
jspdf
23m 38s Feb 19, 2026
REPRO-2026-00101 published
LibreNMS: Time-Based Blind SQL Injection in address-search
CVE-2026-26990 high Security composer
librenms/librenms
11m 33s Feb 19, 2026
REPRO-2026-00100 published
systeminformation: Command Injection via locate Output
CVE-2026-26318 high Security npm
systeminformation
18m 44s Feb 19, 2026
REPRO-2026-00099 published
Semantic Kernel: RCE via InMemoryVectorStore Filter
CVE-2026-26030 critical Security pip
semantic-kernel
25m 13s Feb 19, 2026
REPRO-2026-00098 published
SandboxJS: Host Prototype Pollution via Array Intermediary (Sandbox Escape)
CVE-2026-25881 critical Security npm
@nyariv/sandboxjs
16m 1s Feb 19, 2026
REPRO-2026-00097 published
CASL Ability: Prototype Pollution via Condition Handling
CVE-2026-1774 critical Security npm
@casl/ability
6m 19s Feb 19, 2026
REPRO-2026-00096 published
Milvus: Unauthenticated Access to Restful API on Metrics Port Leading to System Compromise
CVE-2026-26190 critical Security go
github.com/milvus-io/milvus
16m 18s Feb 19, 2026
REPRO-2026-00095 published
Known CMS: Account Takeover via Password Reset Token Leakage
CVE-2026-26273 critical Security composer
idno/known
17m 40s Feb 19, 2026