Vendor
vditor
Products
1
CVEs
2
Across products
2
Status
Private
Products
1- 2 CVEs
Recent CVEs
2| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-34449 | Med | 0.40 | 6.1 | 0.00 | May 3, 2024 | Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true. | ||
| CVE-2024-39150 | Med | 0.38 | 5.9 | 0.00 | Jul 5, 2024 | vditor v.3.9.8 and before is vulnerable to Arbitrary file read via a crafted data packet. |
- risk 0.40cvss 6.1epss 0.00
Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true.
- risk 0.38cvss 5.9epss 0.00
vditor v.3.9.8 and before is vulnerable to Arbitrary file read via a crafted data packet.