CVEs affecting projects tracked on Release Alert, from NVD & OSV.
In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.