Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Ipandao Subscribe
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-9737 1 Ipandao 1 Editor.md 2020-01-06 4.3 MEDIUM 6.1 MEDIUM
Editor.md 1.5.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
CVE-2019-14653 1 Ipandao 1 Editor.md 2019-08-05 4.3 MEDIUM 6.1 MEDIUM
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
CVE-2018-19056 1 Ipandao 1 Editor.md 2018-12-12 4.3 MEDIUM 6.1 MEDIUM
pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element.
CVE-2018-16330 1 Ipandao 1 Editor.md 2018-10-25 4.3 MEDIUM 6.1 MEDIUM
Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.