VYPR
Medium severity6.1NVD Advisory· Published Jul 19, 2021· Updated Jun 17, 2026

CVE-2021-34817

CVE-2021-34817

Description

A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML by importing a crafted pad.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Etherpad/Etherpad2 versions
    cpe:2.3:a:etherpad:etherpad:1.8.13:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:etherpad:etherpad:1.8.13:*:*:*:*:*:*:*
    • (no CPE)range: <1.8.14
  • Etherpad/Etherpaddescription
  • Range: <1.8.14

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.