VYPR

vditor

by vditor

Source repositories

CVEs (2)

  • CVE-2024-34449MedMay 3, 2024
    risk 0.40cvss 6.1epss 0.00

    Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true.

  • CVE-2024-39150MedJul 5, 2024
    risk 0.38cvss 5.9epss 0.00

    vditor v.3.9.8 and before is vulnerable to Arbitrary file read via a crafted data packet.