Skip to content
Noroxi

etherpad records

19 published records for vendor etherpad.

All records

19 records
  • Etherpad Lite before 1.6.4 is exploitable for admin access.

    CriticalCVSS 9.8Proof of conceptEPSS 13%

    etherpad · etherpad liteApr 29, 2018

  • node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access rest

    CriticalCVSS 9.8No exploitEPSS 2%

    etherpad · etherpadFeb 8, 2018

  • Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code.

    CriticalCVSS 9.8No exploitEPSS 2%

    etherpad · etherpadApr 7, 2018

  • Admin privilege escalation and arbitrary code execution via malicious *.etherpad imports

    HighCVSS 8.8No exploitEPSS 2%

    etherpad · etherpadDec 9, 2021

  • CVE-2018-9327
    32Monitor

    Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server.

    HighCVSS 8.1No exploitEPSS 2%

    etherpad · etherpadApr 7, 2018

  • CVE-2015-3297
    31Monitor

    Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by

    HighCVSS 7.5No exploitEPSS 5%

    etherpad · etherpadJul 7, 2017

  • CVE-2015-2298
    31Monitor

    node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an im

    HighCVSS 7.5No exploitEPSS 2%

    etherpad · etherpadJan 12, 2018

  • CVE-2015-4085
    31Monitor

    Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.

    HighCVSS 7.5No exploitEPSS 2%

    etherpad · etherpadSep 7, 2017

  • CVE-2015-3309
    31Monitor

    Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files wi

    HighCVSS 7.5No exploitEPSS 2%

    etherpad · etherpadFeb 13, 2020

  • CVE-2018-9325
    30Monitor

    Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.

    HighCVSS 7.5No exploitEPSS 1%

    etherpad · etherpadApr 7, 2018

  • In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash

    HighCVSS 7.5No exploitEPSS 1%

    etherpad · etherpadApr 28, 2021

  • Etherpad < 1.8.3 is affected by a denial of service in the import functionality.

    HighCVSS 7.5No exploitEPSS 1%

    etherpad · etherpadApr 28, 2021

  • Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service.

    HighCVSS 7.5No exploitEPSS 1%

    etherpad · etherpadApr 28, 2021

  • In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records

    HighCVSS 7.5No exploitEPSS 1%

    etherpad · ueberdbApr 28, 2021

  • An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by i

    HighCVSS 7.2No exploitEPSS 2%

    etherpad · etherpadJul 21, 2021

  • Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files.

    MediumCVSS 6.5No exploitEPSS 1%

    etherpad · etherpadApr 28, 2021

  • A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML b

    MediumCVSS 6.1No exploitEPSS 1%

    etherpad · etherpadJul 19, 2021

  • CVE-2018-6834
    24Monitor

    static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.

    MediumCVSS 6.1No exploitEPSS 1%

    etherpad · etherpad liteFeb 8, 2018

  • templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer

    MediumCVSS 6.1No exploitEPSS 1%

    etherpad · etherpadOct 18, 2019