← Back

Openjsf

openjsf

23 CVEs • 13 products

Products (13)

Click to collapse
Toggle
Express
express
@fastify/middie
Fast Uri
fast-uri
Body Parser
body-parser
Eslint
eslint
Serve Index
serve-index
Dijit
dijit
Electroncord
electroncord
Packager
packager
Serve Static
serve-static
Messageformat
messageformat
Webdriverio
webdriverio

CVEs (23)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
NetappOpenjsf
6Active Iq Unified Manager
Debian LinuxDijit+3 more
Jun 17, 2026
Jun 15, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater...Show more
In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or equal to 1.15.0 and less than 1.15.4, and greater than or equal to 1.16.0 and less than 1.16.3, there is a cross-site scripting vulnerability in the Editor's LinkDialog plugin. This has been fixed in 1.11.11, 1.12.9, 1.13.8, 1.14.7, 1.15.4, 1.16.3.Show less
1Openjsf
1Express
May 13, 2026
Aug 9, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scriptin...Show more
The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.Show less
1Openjsf
1Serve Index
May 13, 2026
Jan 23, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the serve-index package before 1.6.3 for Node.js allows remote attackers to inject arbitrary web script or HTML via a crafted file or directory name.