Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
etherpad etherpad vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2013-7380
The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability
Ep Imageconvert Project Ep Imageconvert
9.8
CVSSv3
CVE-2018-9845
Etherpad Lite prior to 1.6.4 is exploitable for admin access.
Etherpad Etherpad Lite
9.8
CVSSv3
CVE-2018-9326
Etherpad 1.6.3 prior to 1.6.4 allows an malicious user to execute arbitrary code.
Etherpad Etherpad 1.6.3
9.8
CVSSv3
CVE-2018-6835
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote malicious users to bypass intended access restrictions.
Etherpad Etherpad
2 Github repositories
8.8
CVSSv3
CVE-2021-43802
Etherpad is a real-time collaborative editor. In versions before 1.8.16, an attacker can craft an `*.etherpad` file that, when imported, might allow the malicious user to gain admin privileges for the Etherpad instance. This, in turn, can be used to install a malicious Etherpad p...
Etherpad Etherpad
8.1
CVSSv3
CVE-2018-9327
Etherpad 1.5.x and 1.6.x prior to 1.6.4 allows an malicious user to execute arbitrary code on the server. The instance has to be configured to use a document database (DirtyDB, CouchDB, MongoDB, or RethinkDB).
Etherpad Etherpad
7.5
CVSSv3
CVE-2020-22781
In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash the instance).
Etherpad Etherpad
7.5
CVSSv3
CVE-2020-22782
Etherpad < 1.8.3 is affected by a denial of service in the import functionality. Upload of binary file to the import endpoint would crash the instance.
Etherpad Etherpad
7.5
CVSSv3
CVE-2020-22784
In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names.
Etherpad Ueberdb
7.5
CVSSv3
CVE-2020-22785
Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of rate limiting and missing ownership check.
Etherpad Etherpad
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48693
CVE-2024-30851
CVE-2024-34460
CVE-2024-2887
local
CVE-2024-27956
remote code execution
CVE-2024-34475
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »