Skip to content
Noroxi

sencha records

6 published records for vendor sencha.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
50%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18
  2. 19
  3. 20

Bar: total · dark part: CISA KEV.

Attack profile

All records

6 records
  • The getTip() method of Action Columns of Sencha Ext JS 4 to 6 before 6.6.0 is vulnerable to XSS attacks, even when passed HTML-escaped data.

    MediumCVSS 6.1No exploitEPSS 67%

    sencha · ext jsJul 5, 2018

  • CVE-2007-6758
    30Monitor

    Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0.

    HighCVSS 7.5No exploitEPSS 1%

    sencha · ext jsJan 23, 2020

  • CVE-2013-7371
    24Monitor

    node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370

    MediumCVSS 6.1No exploitEPSS 1%

    sencha · connectDec 11, 2019

  • CVE-2013-7370
    24Monitor

    node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware

    MediumCVSS 6.1No exploitEPSS 1%

    sencha · connectDec 11, 2019

  • CVE-2013-4691
    24Monitor

    Sencha Labs Connect has XSS with connect.methodOverride()

    MediumCVSS 6.1No exploitEPSS 1%

    sencha · connectDec 27, 2019

  • CVE-2018-3717
    21Monitor

    connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.j

    MediumCVSS 5.4No exploitEPSS 1%

    sencha · connectJun 6, 2018