Dojotoolkit / Dojo
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2018-1000665 | dojo: Cross-site scripting in i18n-test/unit.html and _base/i18nExhaustive.js | HIGH | 8.0 | Sep 6, 2018 |
| CVE-2018-15494 | dojo: Cross-site scripting (XSS) due to unescaped strings when editing rows in dojox/Grid/DataGrid | CRITICAL | 9.8 | Aug 18, 2018 |
| CVE-2018-6561 | dojo: XSS via the onload attribute of an SVG element | MEDIUM | 6.1 | Feb 2, 2018 |
| CVE-2015-5654 | dojo: cross-site scripting flaw | MEDIUM | 5.4 | Oct 11, 2015 |
| CVE-2010-2276 | The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and… | HIGH | 10.0 | Jun 14, 2010 |
| CVE-2010-2275 | Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script… | MEDIUM | 4.3 | Jun 14, 2010 |
| CVE-2010-2274 | Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow rem… | MEDIUM | 4.3 | Jun 14, 2010 |
| CVE-2010-2273 | Multiple cross-site scripting (XSS) vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.… | MEDIUM | 4.3 | Jun 14, 2010 |
| CVE-2010-2272 | Unspecified vulnerability in iframe_history.html in Dojo 0.4.x before 0.4.4 has unknown impact and remote attack vectors. | HIGH | 10.0 | Jun 14, 2010 |
| CVE-2008-6681 | Cross-site scripting (XSS) vulnerability in dijit.Editor in Dojo before 1.1 allows remote attackers to inject arbitrary web script or HTML via XML entities in… | MEDIUM | 4.3 | Apr 9, 2009 |
| CVE-2007-6726 | Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbi… | MEDIUM | 4.3 | Apr 9, 2009 |
Showing 1 to 11 of 11 CVEs