Known vulnerabilities in the Security plugin
11 security advisories have been published for the Security plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Security - Authentication Bypass (CVE-2026-14495) HIGH
- Security - Broken Access Control (CVE-2025-14270) LOW
- Security - Cross-Site Request Forgery (CSRF) (CVE-2025-14845) MEDIUM
- Security - Cross-Site Scripting (XSS) (CVE-2025-13728) MEDIUM
- Security - Cross-Site Scripting (XSS) (CVE-2025-14393) MEDIUM
- Security - Cross-Site Scripting (XSS) (CVE-2025-11885) MEDIUM
- Security - Cross-Site Scripting (XSS) (CVE-2025-12589) MEDIUM
- Security - Information Disclosure (CVE-2025-6722) MEDIUM
- Security - Authentication Bypass (CVE-2025-6895) CRITICAL
- Security - Cross-Site Request Forgery (CSRF) (CVE-2022-29489) MEDIUM
- Security - Security Vulnerability (CVE-2022-2877) MEDIUM