VYPR
Vendor

Slab

Products
4
CVEs
5
Across products
6
Status
Private

Products

4

Recent CVEs

5
  • CVE-2018-17333CriSep 22, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in libsvg2 through 2012-10-19. A stack-based buffer overflow in svgStringToLength in svg_types.c allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because sscanf is misused.

  • CVE-2026-77972CriSep 15, 2026
    risk 0.52cvss —epss 0.00

    Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS responses to reach internal network destinations that validation rejected. Validation returns a verdict and not the address it approved, so the HTTP clients the…

  • CVE-2026-77866CriSep 15, 2026
    risk 0.52cvss —epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured to block. Only IPv4 addresses are matched against the reserved ranges and the blocklist. Every other…

  • CVE-2025-15056MedJan 13, 2026
    risk 0.40cvss 6.1epss 0.00

    A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS). This issue affects Quill: 2.0.3.

  • CVE-2021-3163MedApr 12, 2021
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in the HTML editor of Slab Quill 4.8.0 allows an attacker to execute arbitrary JavaScript by storing an XSS payload (a crafted onloadstart attribute of an IMG element) in a text field. Note: Researchers have claimed that this issue is not within the product…