CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Organizr v1.90 is vulnerable to Cross Site Scripting (XSS) via api.php.