Vulnerabilities (CVE)

Filtered by vendor Reviewboard Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-31330 1 Reviewboard 1 Review Board 2022-05-20 3.5 LOW 5.4 MEDIUM
A Cross-Site Scripting (XSS) vulnerability exists within Review Board versions 3.0.20 and 4.0 RC1 and earlier. An authenticated attacker may inject malicious Javascript code when using Markdown editing within the application which remains persistent.
CVE-2013-4411 2 Fedoraproject, Reviewboard 2 Fedora, Reviewboard 2019-12-11 4.0 MEDIUM 4.3 MEDIUM
Review Board: URL processing gives unauthorized users access to review lists
CVE-2014-5028 1 Reviewboard 1 Review Board 2018-04-24 4.0 MEDIUM 6.5 MEDIUM
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.