Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
etherpad vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2018-6835
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote malicious users to bypass intended access restrictions.
Etherpad Etherpad
2 Github repositories
5
CVSSv2
CVE-2020-22782
Etherpad < 1.8.3 is affected by a denial of service in the import functionality. Upload of binary file to the import endpoint would crash the instance.
Etherpad Etherpad
6.5
CVSSv2
CVE-2021-34816
An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source.
Etherpad Etherpad 1.8.13
4.3
CVSSv2
CVE-2021-34817
A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote malicious users to inject arbitrary JavaScript or HTML by importing a crafted pad.
Etherpad Etherpad 1.8.13
7.5
CVSSv2
CVE-2018-9326
Etherpad 1.6.3 prior to 1.6.4 allows an malicious user to execute arbitrary code.
Etherpad Etherpad 1.6.3
4.3
CVSSv2
CVE-2018-6834
static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.
Etherpad Etherpad Lite
7.5
CVSSv2
CVE-2018-9845
Etherpad Lite prior to 1.6.4 is exploitable for admin access.
Etherpad Etherpad Lite
4.3
CVSSv2
CVE-2019-18209
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
Etherpad Etherpad 1.7.5
5
CVSSv2
CVE-2020-22784
In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names.
Etherpad Ueberdb
7.5
CVSSv2
CVE-2013-7380
The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability
Ep Imageconvert Project Ep Imageconvert
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4654
CVE-2023-49606
encryption
NULL pointer dereference
CVE-2024-4439
CVE-2024-4649
race condition
CVE-2024-27202
CVE-2024-34566
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2