matrix-react-sdk project records
6 published records for vendor matrix-react-sdk project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2024-47824No exploit | Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a roommatrix-org · matrix-react-sdk · CWE-200 | High8.7 | — | 0.7% | Oct 15, 2024 |
32Monitor | CVE-2023-28103No exploit | Prototype pollution in matrix-react-sdkmatrix-react-sdk project · matrix-react-sdk · CWE-1321 | High8.2 | — | 0.7% | Mar 28, 2023 |
31Monitor | CVE-2021-32622No exploit | File upload local preview can run embedded scripts after user interactionmatrix-react-sdk project · matrix-react-sdk · CWE-74 | High7.8 | — | 0.4% | May 17, 2021 |
21Monitor | CVE-2023-37259No exploit | Cross site scripting in Export Chat featurematrix-react-sdk project · matrix-react-sdk · CWE-79 | Medium5.4 | — | 0.5% | Jul 18, 2023 |
18Monitor | CVE-2023-30609No exploit | matrix-react-sdk vulnerable to HTML injection in search results via plaintext message highlightingmatrix-react-sdk project · matrix-react-sdk · CWE-74 | Medium4.7 | — | 0.6% | Apr 25, 2023 |
17Monitor | CVE-2021-21320No exploit | User content sandbox can be confused into opening arbitrary documentsmatrix-react-sdk project · matrix-react-sdk · CWE-345 | Medium4.3 | — | 0.9% | Mar 1, 2021 |
- CVE-2024-4782434Monitor
Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a room
HighCVSS 8.7No exploitEPSS 1%matrix-org · matrix-react-sdkOct 15, 2024
- CVE-2023-2810332Monitor
Prototype pollution in matrix-react-sdk
HighCVSS 8.2No exploitEPSS 1%matrix-react-sdk project · matrix-react-sdkMar 28, 2023
- CVE-2021-3262231Monitor
File upload local preview can run embedded scripts after user interaction
HighCVSS 7.8No exploitEPSS 0%matrix-react-sdk project · matrix-react-sdkMay 17, 2021
- CVE-2023-3725921Monitor
Cross site scripting in Export Chat feature
MediumCVSS 5.4No exploitEPSS 0%matrix-react-sdk project · matrix-react-sdkJul 18, 2023
- CVE-2023-3060918Monitor
matrix-react-sdk vulnerable to HTML injection in search results via plaintext message highlighting
MediumCVSS 4.7No exploitEPSS 1%matrix-react-sdk project · matrix-react-sdkApr 25, 2023
- CVE-2021-2132017Monitor
User content sandbox can be confused into opening arbitrary documents
MediumCVSS 4.3No exploitEPSS 1%matrix-react-sdk project · matrix-react-sdkMar 1, 2021