CVEs affecting projects tracked on Release Alert, from NVD & OSV.
The dump function in Util/TemplateHelper.php in filp whoops before 2.1.13 has XSS.