Vulnerabilities (CVE)

Filtered by vendor Etherpad Subscribe
Filtered by product Etherpad
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-34817 1 Etherpad 1 Etherpad 2021-07-27 4.3 MEDIUM 6.1 MEDIUM
A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML by importing a crafted pad.
CVE-2020-22783 1 Etherpad 1 Etherpad 2021-05-05 4.0 MEDIUM 6.5 MEDIUM
Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database backend supported by Etherpad.
CVE-2019-18209 1 Etherpad 1 Etherpad 2019-10-22 4.3 MEDIUM 6.1 MEDIUM
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.