VYPR
Vendor

Joget

Products
3
CVEs
4
Across products
7
Status
Private

Products

3

Recent CVEs

4
  • CVE-2019-14352HigJul 28, 2019
    risk 0.51cvss 7.8epss 0.01

    In Joget Workflow 6.0.20, CSV Injection, also known as Formula Injection, exists, as demonstrated by jw/web/userview/crm_community/crm_userview_sales/_/account_new with the Account ID or Account Name field. NOTE: the vendor disputes the relevance of this finding because CSV is…

  • CVE-2022-26197MedMar 25, 2022
    risk 0.35cvss 5.4epss 0.01

    Joget DX 7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Datalist table.

  • CVE-2022-4859LowDec 30, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in Joget up to 7.0.33. This issue affects the function submitForm of the file wflow-core/src/main/java/org/joget/plugin/enterprise/UserProfileMenu.java of the component User Profile Menu. The manipulation of…

  • CVE-2022-4560LowDec 16, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in Joget up to 7.0.31. It has been rated as problematic. This issue affects the function getInternalJsCssLib of the file wflow-core/src/main/java/org/joget/plugin/enterprise/UniversalTheme.java of the component wflow-core. The manipulation of the…