CVEs affecting projects tracked on Release Alert, from NVD & OSV.
ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php.