Vendor
Laborator
Products
5
CVEs
5
Across products
6
Status
Private
Products
5- 3 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 0 CVEs
Recent CVEs
5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-24075 | Med | 0.40 | 6.1 | 0.01 | Aug 11, 2023 | Cross Site Scripting (XSS) vulnerability in Name Input Field in Contact Us form in Laborator Kalium before 3.0.4, allows remote attackers to execute arbitrary code. | ||
| CVE-2020-14010 | Med | 0.40 | 6.1 | 0.01 | Jun 10, 2020 | The Laborator Xenon theme 1.3 for WordPress allows Reflected XSS via the data/typeahead-generate.php q (aka name) parameter. | ||
| CVE-2019-20141 | Med | 0.40 | 6.1 | 0.05 | Dec 30, 2019 | An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter. | ||
| CVE-2020-23576 | Med | 0.35 | 5.4 | 0.01 | Aug 27, 2020 | Laborator Neon dashboard v3 is affected by stored Cross Site Scripting (XSS) via the chat tab. | ||
| CVE-2020-13890 | Med | 0.35 | 5.4 | 0.01 | Jun 6, 2020 | The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard. |
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability in Name Input Field in Contact Us form in Laborator Kalium before 3.0.4, allows remote attackers to execute arbitrary code.
- risk 0.40cvss 6.1epss 0.01
The Laborator Xenon theme 1.3 for WordPress allows Reflected XSS via the data/typeahead-generate.php q (aka name) parameter.
- risk 0.40cvss 6.1epss 0.05
An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter.
- risk 0.35cvss 5.4epss 0.01
Laborator Neon dashboard v3 is affected by stored Cross Site Scripting (XSS) via the chat tab.
- risk 0.35cvss 5.4epss 0.01
The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.