go

github.com/enchant97/note-mark/backend

View on go registry
14 Total advisories
14 Vulnerabilities
0 Malware

Vulnerabilities

MEDIUM 5.9
Go

CVE-2026-40265

Note Mark has Broken Access Control on Asset Download

CRITICAL 9.4
Go

CVE-2026-41571

Note Mark: OIDC-registered users authenticated by submitting password "null"

LOW 3.7
Go

CVE-2026-40263

Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel

CRITICAL 10.0
Go

CVE-2026-44523

Note Mark has a JWT Secret Weakness that allows Full Account Takeover via Token Forgery

UNKNOWN
Go

CVE-2026-41571

Note Mark: OIDC-registered users authenticated by submitting password "null" in github.com/enchant97/note-mark/backend

UNKNOWN
Go

CVE-2026-40263

Note Mark: Username Enumeration via Login Endpoint Timing Side-Channel in github.com/enchant97/note-mark/backend

UNKNOWN
Go

CVE-2026-44523

Note Mark has a JWT Secret Weakness that allows Full Account Takeover via Token Forgery in github.com/enchant97/note-mark/backend

UNKNOWN
Go

CVE-2026-40265

Note Mark has Broken Access Control on Asset Download in github.com/enchant97/note-mark/backend

UNKNOWN
Go

CVE-2026-44522

Note Mark: Arbitrary File Write via Path Traversal in Asset Names Leads to Remote Code Execution

HIGH 8.7
Go

CVE-2026-40262

Note Mark has Stored XSS via Unrestricted Asset Upload

UNKNOWN
Go

CVE-2026-44522

Note Mark: Arbitrary File Write via Path Traversal in Asset Names Leads to Remote Code Execution in github.com/enchant97/note-mark/backend

UNKNOWN
Go

CVE-2026-40262

Note Mark has Stored XSS via Unrestricted Asset Upload in github.com/enchant97/note-mark/backend

MEDIUM 5.3
Go

CVE-2026-41572

Note Mark: Unauthenticated read of notes and assets in soft-deleted public books

UNKNOWN
Go

CVE-2026-41572

Note Mark: Unauthenticated read of notes and assets in soft-deleted public books in github.com/enchant97/note-mark/backend

Ready to move

Start Securing

Free, no credit card | First findings in minutes