Skip to content
Noroxi

Laborator records

5 published records for vendor laborator.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 19
  2. 20
  3. 23

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

Attack profile

All records

5 records
  • An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter.

    MediumCVSS 6.1Proof of conceptEPSS 5%

    laborator · neonDec 30, 2019

  • The Laborator Xenon theme 1.3 for WordPress allows Reflected XSS via the data/typeahead-generate.php q (aka name) parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    laborator · xenonJun 10, 2020

  • Cross Site Scripting (XSS) vulnerability in Name Input Field in Contact Us form in Laborator Kalium before 3.0.4, allows remote attackers to

    MediumCVSS 6.1No exploitEPSS 1%

    laborator · kaliumAug 11, 2023

  • The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.

    MediumCVSS 5.4No exploitEPSS 1%

    laborator · neonJun 6, 2020

  • Laborator Neon dashboard v3 is affected by stored Cross Site Scripting (XSS) via the chat tab.

    MediumCVSS 5.4No exploitEPSS 1%

    laborator · neonAug 27, 2020