etherpad records
19 published records for vendor etherpad.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 10.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-790 Improper Filtering of Special Elements1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2018-9845Proof of concept | Etherpad Lite before 1.6.4 is exploitable for admin access.etherpad · etherpad lite · CWE-178 | Critical9.8 | — | 12.9% | Apr 29, 2018 |
40Plan | CVE-2018-6835No exploit | node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restetherpad · etherpad · CWE-20 | Critical9.8 | — | 2.3% | Feb 8, 2018 |
40Plan | CVE-2018-9326No exploit | Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code.etherpad · etherpad | Critical9.8 | — | 2.0% | Apr 7, 2018 |
36Monitor | CVE-2021-43802No exploit | Admin privilege escalation and arbitrary code execution via malicious *.etherpad importsetherpad · etherpad · CWE-790 | High8.8 | — | 2.0% | Dec 9, 2021 |
32Monitor | CVE-2018-9327No exploit | Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server.etherpad · etherpad · CWE-20 | High8.1 | — | 1.6% | Apr 7, 2018 |
31Monitor | CVE-2015-3297No exploit | Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files byetherpad · etherpad · CWE-22 | High7.5 | — | 5.0% | Jul 7, 2017 |
31Monitor | CVE-2015-2298No exploit | node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an imetherpad · etherpad · CWE-200 | High7.5 | — | 2.3% | Jan 12, 2018 |
31Monitor | CVE-2015-4085No exploit | Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.etherpad · etherpad · CWE-22 | High7.5 | — | 2.3% | Sep 7, 2017 |
31Monitor | CVE-2015-3309No exploit | Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files wietherpad · etherpad · CWE-22 | High7.5 | — | 2.3% | Feb 13, 2020 |
30Monitor | CVE-2018-9325No exploit | Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.etherpad · etherpad · CWE-200 | High7.5 | — | 1.2% | Apr 7, 2018 |
30Monitor | CVE-2020-22781No exploit | In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash etherpad · etherpad · CWE-89 | High7.5 | — | 1.1% | Apr 28, 2021 |
30Monitor | CVE-2020-22782No exploit | Etherpad < 1.8.3 is affected by a denial of service in the import functionality.etherpad · etherpad | High7.5 | — | 1.1% | Apr 28, 2021 |
30Monitor | CVE-2020-22785No exploit | Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service.etherpad · etherpad · CWE-770 | High7.5 | — | 1.1% | Apr 28, 2021 |
30Monitor | CVE-2020-22784No exploit | In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database recordsetherpad · ueberdb · CWE-697 | High7.5 | — | 1.0% | Apr 28, 2021 |
29Monitor | CVE-2021-34816No exploit | An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by ietherpad · etherpad · CWE-88 | High7.2 | — | 2.2% | Jul 21, 2021 |
26Monitor | CVE-2020-22783No exploit | Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files.etherpad · etherpad · CWE-312 | Medium6.5 | — | 0.6% | Apr 28, 2021 |
24Monitor | CVE-2021-34817No exploit | A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML betherpad · etherpad · CWE-79 | Medium6.1 | — | 1.3% | Jul 19, 2021 |
24Monitor | CVE-2018-6834No exploit | static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.etherpad · etherpad lite · CWE-79 | Medium6.1 | — | 0.9% | Feb 8, 2018 |
24Monitor | CVE-2019-18209No exploit | templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Exploreretherpad · etherpad · CWE-79 | Medium6.1 | — | 0.7% | Oct 18, 2019 |
- CVE-2018-984543Plan
Etherpad Lite before 1.6.4 is exploitable for admin access.
CriticalCVSS 9.8Proof of conceptEPSS 13%etherpad · etherpad liteApr 29, 2018
- CVE-2018-683540Plan
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access rest
CriticalCVSS 9.8No exploitEPSS 2%etherpad · etherpadFeb 8, 2018
- CVE-2018-932640Plan
Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code.
CriticalCVSS 9.8No exploitEPSS 2%etherpad · etherpadApr 7, 2018
- CVE-2021-4380236Monitor
Admin privilege escalation and arbitrary code execution via malicious *.etherpad imports
HighCVSS 8.8No exploitEPSS 2%etherpad · etherpadDec 9, 2021
- CVE-2018-932732Monitor
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server.
HighCVSS 8.1No exploitEPSS 2%etherpad · etherpadApr 7, 2018
- CVE-2015-329731Monitor
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by
HighCVSS 7.5No exploitEPSS 5%etherpad · etherpadJul 7, 2017
- CVE-2015-229831Monitor
node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an im
HighCVSS 7.5No exploitEPSS 2%etherpad · etherpadJan 12, 2018
- CVE-2015-408531Monitor
Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.
HighCVSS 7.5No exploitEPSS 2%etherpad · etherpadSep 7, 2017
- CVE-2015-330931Monitor
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files wi
HighCVSS 7.5No exploitEPSS 2%etherpad · etherpadFeb 13, 2020
- CVE-2018-932530Monitor
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.
HighCVSS 7.5No exploitEPSS 1%etherpad · etherpadApr 7, 2018
- CVE-2020-2278130Monitor
In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash
HighCVSS 7.5No exploitEPSS 1%etherpad · etherpadApr 28, 2021
- CVE-2020-2278230Monitor
Etherpad < 1.8.3 is affected by a denial of service in the import functionality.
HighCVSS 7.5No exploitEPSS 1%etherpad · etherpadApr 28, 2021
- CVE-2020-2278530Monitor
Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service.
HighCVSS 7.5No exploitEPSS 1%etherpad · etherpadApr 28, 2021
- CVE-2020-2278430Monitor
In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records
HighCVSS 7.5No exploitEPSS 1%etherpad · ueberdbApr 28, 2021
- CVE-2021-3481629Monitor
An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by i
HighCVSS 7.2No exploitEPSS 2%etherpad · etherpadJul 21, 2021
- CVE-2020-2278326Monitor
Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files.
MediumCVSS 6.5No exploitEPSS 1%etherpad · etherpadApr 28, 2021
- CVE-2021-3481724Monitor
A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML b
MediumCVSS 6.1No exploitEPSS 1%etherpad · etherpadJul 19, 2021
- CVE-2018-683424Monitor
static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.
MediumCVSS 6.1No exploitEPSS 1%etherpad · etherpad liteFeb 8, 2018
- CVE-2019-1820924Monitor
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer
MediumCVSS 6.1No exploitEPSS 1%etherpad · etherpadOct 18, 2019