VYPR

Agora

by Agorafoundation

Source repositories

CVEs (4)

  • CVE-2025-55135MedAug 7, 2025
    risk 0.35cvss 6.4epss 0.00

    In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than PNG, JPEG, and WEBP are permitted by server/routes/userRoutes.js; this includes SVG.

  • CVE-2025-55134MedAug 7, 2025
    risk 0.35cvss 6.4epss 0.00

    In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via tag in client/agora/public/js/editorManager.js.

  • CVE-2025-55133MedAug 7, 2025
    risk 0.35cvss 6.4epss 0.00

    In Agora Foundation Agora fall23-Alpha1 before b087490, there is XSS via topicName in client/agora/public/js/editorManager.js.

  • CVE-2006-7194Apr 18, 2007
    risk 0.03cvss epss 0.05

    PHP remote file inclusion vulnerability in modules/Mysqlfinder/MysqlfinderAdmin.php in Agora 1.4 RC1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the _SESSION[PATH_COMPOSANT] parameter.