CVEs affecting projects tracked on Release Alert, from NVD & OSV.
A cross-site scripting (XSS) vulnerability AntSword v2.0.7 can remotely execute system commands.