prototypejs records
4 published records for vendor prototypejs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 75%
- Median publish → KEV
- No record has entered KEV
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2008-7220Proof of concept | Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests"prototypejs · prototype | High7.5 | — | 13.4% | Sep 13, 2009 |
31Monitor | CVE-2020-27511No exploit | An issue was discovered in the stripTags and unescapeHTML components in Prototype 1.7.3 where an attacker can cause a Regular Expression Denprototypejs · prototype | High7.5 | — | 2.5% | Jun 21, 2021 |
21Monitor | CVE-2007-2383No exploit | The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protectiprototypejs · prototype framework | Medium5.0 | — | 2.4% | Apr 30, 2007 |
17Monitor | CVE-2020-7993No exploit | Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID fielprototypejs · prototype · CWE-862 | Medium4.3 | — | 0.7% | Feb 3, 2020 |
- CVE-2008-722034Monitor
Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests"
HighCVSS 7.5Proof of conceptEPSS 13%prototypejs · prototypeSep 13, 2009
- CVE-2020-2751131Monitor
An issue was discovered in the stripTags and unescapeHTML components in Prototype 1.7.3 where an attacker can cause a Regular Expression Den
HighCVSS 7.5No exploitEPSS 3%prototypejs · prototypeJun 21, 2021
- CVE-2007-238321Monitor
The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protecti
MediumCVSS 5.0No exploitEPSS 2%prototypejs · prototype frameworkApr 30, 2007
- CVE-2020-799317Monitor
Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID fiel
MediumCVSS 4.3No exploitEPSS 1%prototypejs · prototypeFeb 3, 2020