Количество 2
Количество 2
CVE-2022-40011
около 3 лет назад
Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then used at a victim's origin.
CVSS3: 6.1
EPSS: Низкий
GHSA-q28p-82xj-hwh7
около 3 лет назад
Cross Site Scripting (XSS) vulnerability in typora through 1.38 allows remote attackers to run arbitrary code via export from editor.
CVSS3: 6.1
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-40011 Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then used at a victim's origin. | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-q28p-82xj-hwh7 Cross Site Scripting (XSS) vulnerability in typora through 1.38 allows remote attackers to run arbitrary code via export from editor. | CVSS3: 6.1 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу
20