sencha records
6 published records for vendor sencha.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2018-8046No exploit | The getTip() method of Action Columns of Sencha Ext JS 4 to 6 before 6.6.0 is vulnerable to XSS attacks, even when passed HTML-escaped data.sencha · ext js · CWE-79 | Medium6.1 | — | 66.6% | Jul 5, 2018 |
30Monitor | CVE-2007-6758No exploit | Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0.sencha · ext js · CWE-918 | High7.5 | — | 1.3% | Jan 23, 2020 |
24Monitor | CVE-2013-7371No exploit | node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370sencha · connect · CWE-79 | Medium6.1 | — | 1.4% | Dec 11, 2019 |
24Monitor | CVE-2013-7370No exploit | node-connect before 2.8.1 has XSS in the Sencha Labs Connect middlewaresencha · connect · CWE-79 | Medium6.1 | — | 1.4% | Dec 11, 2019 |
24Monitor | CVE-2013-4691No exploit | Sencha Labs Connect has XSS with connect.methodOverride()sencha · connect · CWE-79 | Medium6.1 | — | 0.6% | Dec 27, 2019 |
21Monitor | CVE-2018-3717No exploit | connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.jsencha · connect · CWE-79 | Medium5.4 | — | 1.3% | Jun 6, 2018 |
- CVE-2018-804644Plan
The getTip() method of Action Columns of Sencha Ext JS 4 to 6 before 6.6.0 is vulnerable to XSS attacks, even when passed HTML-escaped data.
MediumCVSS 6.1No exploitEPSS 67%sencha · ext jsJul 5, 2018
- CVE-2007-675830Monitor
Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0.
HighCVSS 7.5No exploitEPSS 1%sencha · ext jsJan 23, 2020
- CVE-2013-737124Monitor
node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370
MediumCVSS 6.1No exploitEPSS 1%sencha · connectDec 11, 2019
- CVE-2013-737024Monitor
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
MediumCVSS 6.1No exploitEPSS 1%sencha · connectDec 11, 2019
- CVE-2013-469124Monitor
Sencha Labs Connect has XSS with connect.methodOverride()
MediumCVSS 6.1No exploitEPSS 1%sencha · connectDec 27, 2019
- CVE-2018-371721Monitor
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.j
MediumCVSS 5.4No exploitEPSS 1%sencha · connectJun 6, 2018