valine.js CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

valine.js vulnerability overview

Aggregates CVE and security vulnerability intelligence across all valine.js-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting and vendor risk denial of service and related security problems, affecting vendor surface production workloads and vendor surface software deployment scenarios.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2022-38545 Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request. [email protected] 9.6 1.65% 2022-09-19 2024-11-21
CVE-2020-28847 Cross Site Scripting (XSS) vulnerability in xCss Valine v1.4.14 via the nick parameter to /classes/Comment. [email protected] 5.4 0.25% 2022-04-05 2024-11-21
CVE-2021-34801 Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agent) value that only specifies the product and version. [email protected] 5.3 1.05% 2021-06-16 2024-11-21
CVE-2018-19289 An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file. [email protected] 6.1 0.29% 2018-11-15 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence