sencha CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

sencha vulnerability overview

Aggregates CVE and security vulnerability intelligence across all sencha-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk cross-site scripting and vendor risk ssrf, with potential vendor impact session compromise across vendor surface production workloads and vendor surface software deployment use cases.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2007-6758 Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0. [email protected] 7.5 1.31% 2020-01-23 2026-06-16
CVE-2013-4691 Sencha Labs Connect has XSS with connect.methodOverride() [email protected] 6.1 0.65% 2019-12-27 2026-06-16
CVE-2013-7371 node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370) [email protected] 6.1 1.24% 2019-12-11 2026-06-17
CVE-2013-7370 node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware [email protected] 6.1 1.22% 2019-12-11 2026-06-17
CVE-2018-8046 The getTip() method of Action Columns of Sencha Ext JS 4 to 6 before 6.6.0 is vulnerable to XSS attacks, even when passed HTML-escaped data. This framework brings no built-in XSS protection, so the developer has to ensure that data is correctly sanitized. However, the getTip() method of Action Columns takes HTML-escaped data and un-escapes it. If the tooltip contains user-controlled data, an attacker could exploit this to create a cross-site scripting attack, even when developers took precaution [email protected] 6.1 67.01% 2018-07-05 2026-06-17
CVE-2018-3717 connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware. [email protected] 5.4 1.31% 2018-06-07 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence