Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: RangeError: Maximum call stack size exceeded — uncontrolled recursion on deep graph data exhausted the JS call stack (client-side DoS)| CVE-2026-67174 | 9.2 CRITICAL | DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pivotick |
| CVE-2026-66918 | 8.2 HIGH | DOM-Based Cross-Site Scripting via Unsanitized SVG Node Icons |
| CVE-2026-66919 | 6.9 MEDIUM | Stored DOM-Based Cross-Site Scripting in Node Modal Headers |
| CVE-2026-66921 | 6.3 MEDIUM | Pivotick - Stored DOM-Based Cross-Site Scripting via Unescaped Markdown Node References |
| CVE-2026-66922 | 5.1 MEDIUM | Pivotick Prototype-Key Collision in Tree Layout and Cycle Detection Allows Graph Manipulat |
| CVE-2026-67173 | 5.1 MEDIUM | Pivotick Unvalidated Node Image URLs Allow Unintended Client-Side Requests |
No comments yet