VendorsNew APInew_apiany version
Vulnerabilities

New API New API any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2025-55573
QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).
Published 2025-08-22 · Analyzed
8.8EPSS 0.004
CVE-2026-41432
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud
Published 2026-05-08 · Analyzed
8.2EPSS 0.008
CVE-2026-33655
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
Published 2026-07-09 · Analyzed
7.7EPSS 0.004
CVE-2026-25802
New API has Potential XSS in its MarkdownRenderer component
Published 2026-02-24 · Analyzed
7.6EPSS 0.003
CVE-2026-25591
New API has an SQL LIKE Wildcard Injection DoS via Token Search
Published 2026-02-24 · Analyzed
7.1EPSS 0.006
CVE-2026-42339
New API: SSRF Filter Bypass via 0.0.0.0
Published 2026-05-08 · Analyzed
7.1EPSS 0.003
CVE-2026-30886
New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check
Published 2026-03-23 · Analyzed
6.5EPSS 0.004
CVE-2026-44342
New API CSRF in email and WeChat account binding endpoints
Published 2026-07-09 · Analyzed
5.3EPSS 0.002
CVE-2026-32879
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure
Published 2026-03-23 · Analyzed
4.9EPSS 0.005