CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams. As a result, a crafted PlantUML diag...Show more |
2Fedoraproject Plantuml2Fedora PlantumlNov 21, 2024 Jun 27, 2023 N/A· v4 10.0 CRITICAL· v3 N/A· v2 Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9. |
2Fedoraproject Plantuml2Fedora PlantumlNov 21, 2024 Jun 27, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9. |
2Fedoraproject Plantuml2Fedora PlantumlNov 21, 2024 May 14, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request...Show more |
2Fedoraproject Plantuml2Fedora PlantumlNov 21, 2024 Apr 15, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets t...Show more |