CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.