stefanprodan CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

stefanprodan vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to stefanprodan, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-43644 podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints where the echoHandler writes request body content directly to the response without setting explicit Content-Type or X-Content-Type-Options headers. Attackers can craft cross-origin HTML pages with auto-submitting forms containing script payloads in the request body, which are served as text/html due to Go's content type detection, allowing the reflected script to execute in the pod [email protected] 5.1 0.03% 2026-05-14 2026-06-01
CVE-2025-70849 Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST request to the /store endpoint. The application renders uploaded content without a restrictive Content-Security-Policy (CSP) or adequate Content-Type validation, leading to Stored Cross-Site Scripting (XSS). [email protected] 6.1 0.01% 2026-02-03 2026-02-11
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence