Vulnerabilities (CVE)

Filtered by vendor Mycolorway Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-19048 1 Mycolorway 1 Simditor 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Simditor through 2.3.21 allows DOM XSS via an onload attribute within a malformed SVG element.
CVE-2018-6464 1 Mycolorway 1 Simditor 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Simditor v2.3.11 allows XSS via crafted use of svg/onload=alert in a TEXTAREA element, as demonstrated by Firefox 54.0.1.