CVEs affecting projects tracked on Release Alert, from NVD & OSV.
An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project.