Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Editor\.md
(Ipandao)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 8 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2023-04-04 | CVE-2020-19697 | Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script in the <iframe>src parameter. | Editor\.md | 6.1 | ||
2023-04-04 | CVE-2020-19698 | Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the editor parameter. | Editor\.md | 6.1 | ||
2023-05-01 | CVE-2023-29641 | Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script or HTML via crafted markdown text. | Editor\.md | 6.1 | ||
2023-05-08 | CVE-2020-19660 | Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url values. | Editor\.md | 6.1 | ||
2019-03-13 | CVE-2019-9737 | Editor.md 1.5.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring. | Editor\.md | N/A | ||
2019-08-03 | CVE-2019-14653 | pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element. | Editor\.md | 6.1 | ||
2018-11-07 | CVE-2018-19056 | pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element. | Editor\.md | 6.1 | ||
2018-09-02 | CVE-2018-16330 | Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element. | Editor\.md | 6.1 |