Open Issues Need Help
View All on GitHub Password reset token exposed in plaintext logs 27 days ago
bug good first issue level:critical type:security mentor:Ayushh-Sharmaa GSSoC'26 website priority:low needs-more-info NSOC'26
Command injection risk in backup file path verification about 1 month ago
bug good first issue level:critical type:security mentor:Ayushh-Sharmaa GSSoC'26 website priority:low needs-more-info NSOC'26
bug good first issue level:critical type:security mentor:Ayushh-Sharmaa GSSoC'26 website priority:low needs-more-info NSOC'26
Unauthenticated resource creation endpoint allows content injection about 1 month ago
bug good first issue level:critical type:security mentor:Ayushh-Sharmaa GSSoC'26 website priority:low needs-more-info NSOC'26
SQL injection via string interpolation in eventsRepository about 1 month ago
bug good first issue level:critical type:security mentor:Ayushh-Sharmaa GSSoC'26 website priority:low needs-more-info NSOC'26 possible-duplicate
SQL injection risk via table name interpolation in multiple server modules about 2 months ago
bug good first issue level:critical type:security mentor:Ayushh-Sharmaa GSSoC'26 website priority:high needs-more-info NSOC'26
Gemini API key exposed in frontend JavaScript bundle about 2 months ago
bug good first issue level:critical type:security mentor:Ayushh-Sharmaa GSSoC'26 website ai priority:high needs-more-info NSOC'26
Admin login function references undefined variables — broken authentication logic about 2 months ago
bug good first issue level:critical type:security type:bug mentor:Ayushh-Sharmaa GSSoC'26 admin-dashboard priority:high needs-more-info NSOC'26
Unauthenticated read/write access to all users notification preferences about 2 months ago
bug good first issue level:critical type:security mentor:Ayushh-Sharmaa GSSoC'26 admin-dashboard priority:high needs-more-info NSOC'26