CVE-2023-26449
The “OX Chat” web service did not specify a media-type…
Functions with insufficient randomness were used to generate authorization tokens…
Full-text autocomplete search allows user-provided SQL syntax to be injected…
Frontend themes are defined by user-controllable jslob settings and could…