- SEC-1395[listenbrainz-server] CVE-2025-25977: canvg < 4.0.3
- SEC-1394[listenbrainz-server] CVE-2025-25977: canvg <= 4.0.2
- SEC-1393[listenbrainz-server] CVE-2025-27789: @babel/runtime < 7.26.10
- SEC-1392[listenbrainz-server] CVE-2025-27789: @babel/helpers < 7.26.10
- SEC-1391[listenbrainz-server] CVE-2025-27789: @babel/runtime-corejs3 < 7.26.10
- SEC-1390[metabrainz.org] CVE-2025-27789: @babel/helpers < 7.26.10
- SEC-1388[picard-docs] CVE-2025-27516: Jinja2 <= 3.1.5
- SEC-1387[critiquebrainz] CVE-2025-27516: Jinja2 <= 3.1.5
- SEC-1386[bookbrainz-user-guide] CVE-2025-27516: Jinja2 <= 3.1.5
- SEC-1385[metabrainz.org] CVE-2025-27516: Jinja2 <= 3.1.5
- SEC-1381[brainzbot-core] CVE-2025-27516: Jinja2 <= 3.1.5
- SEC-1379[bookbrainz-data-js] CVE-2024-11831: serialize-javascript >= 6.0.0, < 6.0.2
- SEC-1377[bookbrainz-data-js] CVE-2024-11831: serialize-javascript < 6.0.2
- SEC-1376[bookbrainz-site] CVE-2024-11831: serialize-javascript < 6.0.2
- SEC-1375[bookbrainz-site] CVE-2025-26791: dompurify < 3.2.4
- SEC-1363[critiquebrainz] CVE-2024-56201: jinja2 <= 3.1.4
- SEC-1360[picard-docs] CVE-2024-56201: jinja2 <= 3.1.4
- SEC-1354[brainzbot-core] CVE-2024-56326: jinja2 <= 3.1.4
- SEC-1353[brainzbot-core] CVE-2024-56201: jinja2 <= 3.1.4
- SEC-1333[data-set-hoster] CVE-2024-49766: Werkzeug <= 3.0.5
- SEC-1332[data-set-hoster] CVE-2024-49767: werkzeug <= 3.0.5
- SEC-1331[artwork-redirect] CVE-2024-49766: Werkzeug <= 3.0.5
- SEC-1330[artwork-redirect] CVE-2024-49767: werkzeug <= 3.0.5
- SEC-1283[bookbrainz-site] CVE-2024-6531: bootstrap >= 4.0.0, <= 4.6.2
- SEC-1321[brainzbot-core] CVE-2024-45231: Django < 4.2.16
- SEC-1294[brainzbot-core] CVE-2022-36359: Django < 3.2.15
- SEC-1282[critiquebrainz] CVE-2024-6484: bootstrap >= 2.0.0, <= 3.4.1
- SEC-1209[brainzbot-core] CVE-2024-24680: django < 3.2.24
- SEC-1236[brainzbot-core] CVE-2024-34064: Jinja2 < 3.1.4
- SEC-1004[brainzbot-core] CVE-2021-44420: Django < 2.2.25
- SEC-1073[brainzbot-core] CVE-2023-32681: requests >= 2.3.0, < 2.31.0
- SEC-1251[brainzbot-core] CVE-2024-35195: requests < 2.32.0
- SEC-1201[brainzbot-core] CVE-2024-22195: jinja2 < 3.1.3
1 of 33