VYPR
Vendor

Sencha

Products
3
CVEs
8
Across products
8
Status
Private

Products

3

Recent CVEs

8
  • CVE-2007-6758HigJan 23, 2020
    risk 0.49cvss 7.5epss 0.01

    Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0.

  • CVE-2018-8046MedJul 5, 2018
    risk 0.45cvss 6.1epss 0.67

    The getTip() method of Action Columns of Sencha Ext JS 4 to 6 before 6.6.0 is vulnerable to XSS attacks, even when passed HTML-escaped data. This framework brings no built-in XSS protection, so the developer has to ensure that data is correctly sanitized. However, the getTip()…

  • CVE-2013-4691MedDec 27, 2019
    risk 0.40cvss 6.1epss 0.01

    Sencha Labs Connect has XSS with connect.methodOverride()

  • CVE-2013-7371MedDec 11, 2019
    risk 0.33cvss 6.1epss 0.01

    node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370)

  • CVE-2013-7370MedDec 11, 2019
    risk 0.33cvss 6.1epss 0.01

    node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware

  • CVE-2018-3717MedJun 7, 2018
    risk 0.28cvss 5.4epss 0.01

    connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.

  • CVE-2012-1237Apr 6, 2012
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack the authentication of arbitrary users.

  • CVE-2006-6413Dec 10, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Amateras sns 3.11 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.