Записи froala
9 опубликованных записей вендора froala.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 55,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
37Наблюдать | CVE-2021-28114Эксплойта нет | Froala WYSIWYG Editor 3.2.6-1 is affected by XSS due to a namespace confusion during parsing.froala · froala editor · CWE-79 | Средняя5,4 | — | 52,0 % | 16 июл. 2021 г. |
25Наблюдать | CVE-2019-19935Эксплойта нет | Froala Editor before 3.2.3 allows XSS.froala · froala editor · CWE-79 | Средняя6,1 | — | 1,8 % | 7 июл. 2020 г. |
24Наблюдать | CVE-2021-30109Proof of concept | Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS).froala · froala editor · CWE-79 | Средняя6,1 | — | 1,2 % | 5 апр. 2021 г. |
24Наблюдать | CVE-2023-42426Proof of concept | Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert lfroala · froala editor · CWE-79 | Средняя6,1 | — | 1,0 % | 25 сент. 2023 г. |
24Наблюдать | CVE-2020-22864Эксплойта нет | A cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor 3.1.0 allows attackers to execute arbitraryfroala · froala editor · CWE-79 | Средняя6,1 | — | 0,9 % | 26 окт. 2021 г. |
24Наблюдать | CVE-2023-43263Proof of concept | A Cross-site scripting (XSS) vulnerability in Froala Editor v.4.1.1 allows attackers to execute arbitrary code via the Markdown component.froala · froala editor · CWE-79 | Средняя6,1 | — | 0,7 % | 27 сент. 2023 г. |
24Наблюдать | CVE-2020-26523Эксплойта нет | Froala Editor before 3.2.2 allows XSS via pasted content.froala · froala editor · CWE-79 | Средняя6,1 | — | 0,7 % | 2 окт. 2020 г. |
24Наблюдать | CVE-2024-51434Эксплойта нет | Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier.CWE-79 | Средняя6,1 | — | 0,4 % | 7 нояб. 2024 г. |
21Наблюдать | CVE-2023-41592Эксплойта нет | Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability.froala · froala editor · CWE-79 | Средняя5,4 | — | 1,0 % | 14 сент. 2023 г. |
- CVE-2021-2811437Наблюдать
Froala WYSIWYG Editor 3.2.6-1 is affected by XSS due to a namespace confusion during parsing.
СредняяCVSS 5,4Эксплойта нетEPSS 52 %froala · froala editor16 июл. 2021 г.
- CVE-2019-1993525Наблюдать
Froala Editor before 3.2.3 allows XSS.
СредняяCVSS 6,1Эксплойта нетEPSS 2 %froala · froala editor7 июл. 2020 г.
- CVE-2021-3010924Наблюдать
Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS).
СредняяCVSS 6,1Proof of conceptEPSS 1 %froala · froala editor5 апр. 2021 г.
- CVE-2023-4242624Наблюдать
Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert l
СредняяCVSS 6,1Proof of conceptEPSS 1 %froala · froala editor25 сент. 2023 г.
- CVE-2020-2286424Наблюдать
A cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor 3.1.0 allows attackers to execute arbitrary
СредняяCVSS 6,1Эксплойта нетEPSS 1 %froala · froala editor26 окт. 2021 г.
- CVE-2023-4326324Наблюдать
A Cross-site scripting (XSS) vulnerability in Froala Editor v.4.1.1 allows attackers to execute arbitrary code via the Markdown component.
СредняяCVSS 6,1Proof of conceptEPSS 1 %froala · froala editor27 сент. 2023 г.
- CVE-2020-2652324Наблюдать
Froala Editor before 3.2.2 allows XSS via pasted content.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %froala · froala editor2 окт. 2020 г.
- CVE-2024-5143424Наблюдать
Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %7 нояб. 2024 г.
- CVE-2023-4159221Наблюдать
Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %froala · froala editor14 сент. 2023 г.