CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.