Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Appwrite Subscribe
Filtered by product Appwrite
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-2925 1 Appwrite 1 Appwrite 2022-09-13 N/A 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository appwrite/appwrite prior to 1.0.0-RC1.
CVE-2021-23682 2 Appwrite, Litespeed.js Project 2 Appwrite, Litespeed.js 2022-02-23 7.5 HIGH 9.8 CRITICAL
This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the result object is not properly sanitized leading to a Prototype Pollution vulnerability.