Matrix-React-Sdk
Matrix-Org · 8 CVEs
CVE-2024-47824
HIGH
Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a room
Oct 15, 2024
CVE-2024-42347
MEDIUM
URL preview setting for a room is controllable by the homeserver in matrix-react-sdk
Aug 6, 2024
CVE-2023-37259
MEDIUM
Cross site scripting in Export Chat feature
Jul 18, 2023
CVE-2023-30609
HIGH
matrix-react-sdk vulnerable to HTML injection in search results via plaintext message highlighting
Apr 25, 2023
CVE-2022-36060
HIGH
Prototype pollution in matrix-react-sdk
Mar 28, 2023
CVE-2023-28103
HIGH
Prototype pollution in matrix-react-sdk
Mar 28, 2023
CVE-2021-32622
HIGH
File upload local preview can run embedded scripts after user interaction
May 17, 2021
CVE-2021-21320
MEDIUM
User content sandbox can be confused into opening arbitrary documents
Mar 2, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-47824 | Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a room | HIGH | 0.66% | Oct 15, 2024 |
| CVE-2024-42347 | URL preview setting for a room is controllable by the homeserver in matrix-react-sdk | MEDIUM | 0.43% | Aug 6, 2024 |
| CVE-2023-37259 | Cross site scripting in Export Chat feature | MEDIUM | 0.45% | Jul 18, 2023 |
| CVE-2023-30609 | matrix-react-sdk vulnerable to HTML injection in search results via plaintext message highlighting | HIGH | 0.62% | Apr 25, 2023 |
| CVE-2022-36060 | Prototype pollution in matrix-react-sdk | HIGH | 0.91% | Mar 28, 2023 |
| CVE-2023-28103 | Prototype pollution in matrix-react-sdk | HIGH | 0.71% | Mar 28, 2023 |
| CVE-2021-32622 | File upload local preview can run embedded scripts after user interaction | HIGH | 0.37% | May 17, 2021 |
| CVE-2021-21320 | User content sandbox can be confused into opening arbitrary documents | MEDIUM | 0.92% | Mar 2, 2021 |
Showing 1 to 8 of 8 CVEs