Dojotoolkit
Dojotoolkit Dojo: vulnerabilidades y CVE
Dojotoolkit Dojo tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-1000665 | Media (6.1) | 1.3% | — | 6 sept 2018 | Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and… |
| CVE-2018-15494 | Crítica (9.8) | 2.5% | — | 18 ago 2018 | In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid. |
| CVE-2018-6561 | Media (6.1) | 1.2% | — | 2 feb 2018 | dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element. |
| CVE-2015-5654 | Media (4.3) | 2.2% | — | 11 oct 2015 | Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2010-2276 | Alta (10) | 3.2% | — | 15 jun 2010 | The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 has the copyTests=true and mini=false… |
| CVE-2010-2275 | Media (4.3) | 2.9% | — | 15 jun 2010 | Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demonstrated by an… |
| CVE-2010-2274 | Media (4.3) | 1.9% | — | 15 jun 2010 | Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and… |
| CVE-2010-2273 | Media (4.3) | 4.5% | — | 15 jun 2010 | Multiple cross-site scripting (XSS) vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to inject arbitrary web script or… |
| CVE-2010-2272 | Alta (10) | 1.3% | — | 15 jun 2010 | Unspecified vulnerability in iframe_history.html in Dojo 0.4.x before 0.4.4 has unknown impact and remote attack vectors. |
| CVE-2008-6681 | Media (4.3) | 1.1% | — | 9 abr 2009 | Cross-site scripting (XSS) vulnerability in dijit.Editor in Dojo before 1.1 allows remote attackers to inject arbitrary web script or HTML via XML entities in a TEXTAREA element. |
| CVE-2007-6726 | Media (4.3) | 3.4% | — | 9 abr 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving… |