Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2021-43802
Etherpad is a real-time collaborative editor. In versions prior to 1.8.16, an attacker can craft an `*.etherpad` file that, when imported, might allo…
Etherpad
1.8.16+
HIGH 7.2
CVE-2021-34816
An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing…
Etherpad
No fix yet
MEDIUM 6.1
CVE-2021-34817
A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML by importi…
Etherpad
Patch available
HIGH 7.5
CVE-2020-22781
In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash the insta…
Etherpad
1.8.3+
HIGH 7.5
CVE-2020-22782
Etherpad < 1.8.3 is affected by a denial of service in the import functionality. Upload of binary file to the import endpoint would crash the instanc…
Etherpad
1.8.3+
HIGH 7.5
CVE-2020-22784
In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using Ue…
Ueberdb
1.4.8+
HIGH 7.5
CVE-2020-22785
Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with e…
Etherpad
1.8.3+
MEDIUM 6.5
CVE-2020-22783
Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database backend supported by Etherpad.
Etherpad
1.8.3+
HIGH 7.5
CVE-2015-3309
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files with permis…
Etherpad
after 1.5.4
MEDIUM 6.1
CVE-2019-18209
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
Etherpad
Patch available
CRITICAL 9.8
CVE-2018-9845EPSS 13%
Etherpad Lite before 1.6.4 is exploitable for admin access.
Etherpad Lite
1.6.4+
CRITICAL 9.8
CVE-2018-9326
Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code.
Etherpad
No fix yet
HIGH 8.1
CVE-2018-9327
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be configured to use a document…
Etherpad
1.6.4+
HIGH 7.5
CVE-2018-9325
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.
Etherpad
1.6.4+
CRITICAL 9.8
CVE-2018-6835
node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.
Etherpad
1.6.3+
MEDIUM 6.1
CVE-2018-6834
static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.
Etherpad Lite
1.6.3+
HIGH 7.5
CVE-2015-2298
node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an improper su…
Etherpad
Patch available
HIGH 7.5
CVE-2015-4085
Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.
Etherpad
after 1.6.0
HIGH 7.5
CVE-2015-3297
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by leveragi…
Etherpad
Patch available