Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: pkgsRocm.midivisualizer

Found 14 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-91707
5.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 2 days, 20 hours ago Activity log
  • Created suggestion
Divi <= 5.11.1 - Missing Authorization to Unauthenticated Arbitrary Registered Shortcode Execution via 'content' Parameter via Shortcode Module REST Endpoint

The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.11.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. When the 'Force Enable D4 Shortcode Framework' option is enabled, this includes invoking the et_pb_contact_form shortcode to send email to an attacker-selected recipient with attacker-controlled content.

Affected products

Divi
  • =<5.11.1

Matching in nixpkgs

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3

pkgs.pkgsRocm.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3

Package maintainers

Untriaged
created 4 days, 20 hours ago Activity log
  • Created suggestion
Visualizer < 4.0.8 - Contributor+ Stored XSS via JSON Data Source

The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before outputting it back in the chart editor, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any higher-privileged user, such as an administrator, who reviews the affected chart.

References

Affected products

Visualizer
  • <4.0.8

Matching in nixpkgs

pkgs.dbvisualizer

Universal database tool

  • nixos-unstable -
  • nixos-26.05 -

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3

pkgs.ttnn-visualizer

Tool for visualizing and analyzing TT-NN model execution

  • nixos-unstable -
    • nixos-unstable-small

pkgs.pulse-visualizer

Real-time audio visualizer inspired by MiniMeters

  • nixos-unstable -
    • nixos-unstable-small 1.3.9
  • nixos-26.05 -
    • nixos-26.05-small 1.3.9

pkgs.pkgsRocm.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3
Untriaged
Permalink CVE-2026-86779
2.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 week, 2 days ago Activity log
  • Created suggestion
Visualizer < 4.0.6 - Contributor+ Arbitrary Chart Deletion via deleteChart

The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above to permanently delete any chart on the site, including charts created by other users such as administrators.

References

Affected products

Visualizer
  • <4.0.6

Matching in nixpkgs

pkgs.dbvisualizer

Universal database tool

  • nixos-unstable -
  • nixos-26.05 -

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3

pkgs.ttnn-visualizer

Tool for visualizing and analyzing TT-NN model execution

  • nixos-unstable -
    • nixos-unstable-small

pkgs.pulse-visualizer

Real-time audio visualizer inspired by MiniMeters

  • nixos-unstable -
    • nixos-unstable-small 1.3.9
  • nixos-26.05 -
    • nixos-26.05-small 1.3.9

pkgs.pkgsRocm.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3
Untriaged
Permalink CVE-2026-86782
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 week, 2 days ago Activity log
  • Created suggestion
Visualizer < 4.0.6 - Contributor+ Arbitrary Post/Page Modification via IDOR

The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, rename, and overwrite the content of posts and pages they do not own, including other users' private drafts.

References

Affected products

Visualizer
  • <4.0.6

Matching in nixpkgs

pkgs.dbvisualizer

Universal database tool

  • nixos-unstable -
  • nixos-26.05 -

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3

pkgs.ttnn-visualizer

Tool for visualizing and analyzing TT-NN model execution

  • nixos-unstable -
    • nixos-unstable-small

pkgs.pulse-visualizer

Real-time audio visualizer inspired by MiniMeters

  • nixos-unstable -
    • nixos-unstable-small 1.3.9
  • nixos-26.05 -
    • nixos-26.05-small 1.3.9

pkgs.pkgsRocm.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-4361
5.0 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 2 weeks, 1 day ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Divi <= 4.27.6 - Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameter

The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` function using `wp_remote_get()` instead of `wp_safe_remote_get()` to fetch a remote image URL, which does not restrict requests to private or reserved IP ranges. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application server. The response body is not returned to the attacker (blind SSRF), but two oracles exist: a status oracle (the returned URL string differs depending on whether the target responded with HTTP 200) and a timing oracle (response time varies by target reachability).

Affected products

Divi
  • =<4.27.6

Matching in nixpkgs

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable 7.3
    • nixpkgs-unstable 7.3
    • nixos-unstable-small 7.3
  • nixos-26.05 7.3
    • nixos-26.05-small 7.3
    • nixpkgs-26.05-darwin 7.3

Package maintainers

Untriaged
Permalink CVE-2026-3853
6.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 2 weeks, 1 day ago Activity log
  • Created suggestion
Divi <= 4.27.6 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Slider 'image_src' Shortcode Parameter

The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions up to, and including, 4.27.6. This is due to the `image_src` field not being included in the `$url_options` whitelist (which only contains `url`, `button_link`, `button_url`), so it never receives `esc_url_raw()` at save time. On the server side, the value is rendered into a `data-image` HTML attribute using `esc_attr()`, which encodes double quotes as `&quot;`. However, the client-side JavaScript carousel code in `custom.unified.js` reads this attribute using jQuery's `.data('image')`, which returns the browser-decoded value (with `&quot;` decoded back to `"`). The decoded value is then concatenated directly into an HTML string and injected into the DOM via `jQuery.after()` without re-escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user hovers over the carousel thumbnail.

Affected products

Divi
  • =<4.27.6

Matching in nixpkgs

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3

pkgs.pkgsRocm.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3

Package maintainers

Untriaged
Permalink CVE-2026-3852
6.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 2 weeks, 3 days ago Activity log
  • Created suggestion
Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Media Follow 'skype_url' Shortcode Parameter

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media Follow module in all versions up to, and including, 4.27.6. This is due to a three-part sanitization failure: (1) the `skype_url` field is not included in the `$url_options` whitelist in `class-et-builder-element.php`, so it never invokes `esc_url_raw()` during shortcode processing, (2) the render code in `SocialMediaFollowItem.php` explicitly skips `esc_url()` for Skype URLs (`! $is_skype ? esc_url( $url ) : $skype_url`), and (3) only `sanitize_text_field()` is applied, which preserves single and double quote characters allowing attribute breakout. The unsanitized value is interpolated directly into a single-quoted `href` attribute (`href='{$social_network_link_url}'`). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user interacts with the injected element.

Affected products

Divi
  • =<4.27.6

Matching in nixpkgs

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3

pkgs.pkgsRocm.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable -
    • nixos-unstable-small 7.3
  • nixos-26.05 -
    • nixos-26.05-small 7.3

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-3850
6.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 2 weeks, 4 days ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt dismissed (not in Nixpkgs)
Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Contact Form 'redirect_url' Shortcode Parameter

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and including, 4.27.6. This is due to the `redirect_url` attribute being sanitized with `esc_attr()` instead of `esc_url()` before being rendered into the `data-redirect_url` HTML data attribute. Additionally, `redirect_url` is absent from the hardcoded `$url_options` array in `class-et-builder-element.php`, so it does not receive `esc_url_raw()` sanitization during shortcode parsing. After a successful form submission, client-side JavaScript reads this data attribute and passes it directly to `window.location.href`, executing arbitrary JavaScript from a `javascript:` URI. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that execute whenever a user submits the contact form.

Affected products

Divi
  • =<4.27.5

Matching in nixpkgs

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable 7.3
    • nixpkgs-unstable 7.3
    • nixos-unstable-small 7.3
  • nixos-26.05 7.3
    • nixos-26.05-small 7.3
    • nixpkgs-26.05-darwin 7.3

Package maintainers

Dismissed
(not in Nixpkgs)
Permalink CVE-2026-3851
6.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 2 weeks, 4 days ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt dismissed (not in Nixpkgs)
Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Dynamic Content (Legacy JSON Format) Shortcode

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and including, 4.27.6. This is due to two compounding flaws: (1) the save-time sanitization filter `et_builder_sanitize_dynamic_content_fields()` only searches for dynamic content markers in the `@ET-DC@...@` format, but the rendering engine also supports a legacy JSON format that is silently converted at render time, completely bypassing the save-time filter, and (2) the `post_meta_key` resolver in `et_builder_filter_resolve_default_dynamic_content()` does not apply `wp_kses_post()` to the resolved meta value when `enable_html` is set to `on`, passing raw `get_post_meta()` output directly to the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Affected products

Divi
  • =<4.27.6

Matching in nixpkgs

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable 7.3
    • nixpkgs-unstable 7.3
    • nixos-unstable-small 7.3
  • nixos-26.05 7.3
    • nixos-26.05-small 7.3
    • nixpkgs-26.05-darwin 7.3

Package maintainers

Dismissed
(not in Nixpkgs)
updated 1 month ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL

The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attributes, allowing users with a role as low as contributor to store JavaScript which will run when a higher privileged user, such as an administrator, views the post.

References

Affected products

Divi
  • <5.9.0

Matching in nixpkgs

pkgs.midivisualizer

Small MIDI visualizer tool, using OpenGL

  • nixos-unstable 7.3
    • nixpkgs-unstable 7.3
    • nixos-unstable-small 7.3
  • nixos-26.05 7.3
    • nixos-26.05-small 7.3
    • nixpkgs-26.05-darwin 7.3

Package maintainers