CVEs affecting projects tracked on Release Alert, from NVD & OSV.
An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.