Laborator records
5 published records for vendor laborator.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2019-20141Proof of concept | An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter.laborator · neon · CWE-79 | Medium6.1 | — | 5.0% | Dec 30, 2019 |
24Monitor | CVE-2020-14010No exploit | The Laborator Xenon theme 1.3 for WordPress allows Reflected XSS via the data/typeahead-generate.php q (aka name) parameter.laborator · xenon · CWE-79 | Medium6.1 | — | 0.9% | Jun 10, 2020 |
24Monitor | CVE-2020-24075No exploit | Cross Site Scripting (XSS) vulnerability in Name Input Field in Contact Us form in Laborator Kalium before 3.0.4, allows remote attackers tolaborator · kalium · CWE-79 | Medium6.1 | — | 0.5% | Aug 11, 2023 |
21Monitor | CVE-2020-13890No exploit | The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.laborator · neon · CWE-79 | Medium5.4 | — | 0.5% | Jun 6, 2020 |
21Monitor | CVE-2020-23576No exploit | Laborator Neon dashboard v3 is affected by stored Cross Site Scripting (XSS) via the chat tab.laborator · neon · CWE-79 | Medium5.4 | — | 0.5% | Aug 27, 2020 |
- CVE-2019-2014126Monitor
An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter.
MediumCVSS 6.1Proof of conceptEPSS 5%laborator · neonDec 30, 2019
- CVE-2020-1401024Monitor
The Laborator Xenon theme 1.3 for WordPress allows Reflected XSS via the data/typeahead-generate.php q (aka name) parameter.
MediumCVSS 6.1No exploitEPSS 1%laborator · xenonJun 10, 2020
- CVE-2020-2407524Monitor
Cross Site Scripting (XSS) vulnerability in Name Input Field in Contact Us form in Laborator Kalium before 3.0.4, allows remote attackers to
MediumCVSS 6.1No exploitEPSS 1%laborator · kaliumAug 11, 2023
- CVE-2020-1389021Monitor
The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.
MediumCVSS 5.4No exploitEPSS 1%laborator · neonJun 6, 2020
- CVE-2020-2357621Monitor
Laborator Neon dashboard v3 is affected by stored Cross Site Scripting (XSS) via the chat tab.
MediumCVSS 5.4No exploitEPSS 1%laborator · neonAug 27, 2020