VYPR

NuGetGallery

by Microsoft

Source repositories

CVEs (4)

  • CVE-2020-1340MedJun 9, 2020
    risk 0.35cvss 5.4epss 0.02

    A spoofing vulnerability exists when the NuGetGallery does not properly sanitize input on package metadata values, aka 'NuGetGallery Spoofing Vulnerability'.

  • CVE-2024-54138MedDec 6, 2024
    risk 0.00cvss 6.1epss 0.00

    NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately sanitize autolinks.…

  • CVE-2024-47604HigOct 1, 2024
    risk 0.00cvss 8.2epss 0.01

    NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser.

  • CVE-2024-37304MedJun 12, 2024
    risk 0.00cvss 6.1epss 0.01

    NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately sanitize autolinks.…