Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Api Bearer Auth Project Subscribe
Filtered by product Api Bearer Auth
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-16332 1 Api Bearer Auth Project 1 Api Bearer Auth 2019-10-08 4.3 MEDIUM 6.1 MEDIUM
In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS.