VYPR
Vendor

Valine.js

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2022-38545CriSep 19, 2022
    risk 0.58cvss 9.6epss 0.33

    Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2020-28847MedApr 5, 2022
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting (XSS) vulnerability in xCss Valine v1.4.14 via the nick parameter to /classes/Comment.

  • CVE-2021-34801MedJun 16, 2021
    risk 0.35cvss 5.3epss 0.02

    Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agent) value that only specifies the product and version.

  • CVE-2018-19289MedNov 15, 2018
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.