Known Vulnerabilities for Lol-html by Cloudflare
Listed below are 1 of the newest known vulnerabilities associated with "Lol-html" by "Cloudflare".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-41459 json | Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthenticated a... | Not Provided | 2026-04-22 | 2026-04-22 |
| CVE-2026-41241 json | pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submission tit... | Not Provided | 2026-04-23 | 2026-04-23 |
| CVE-2026-41240 json | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsisten... | Not Provided | 2026-04-23 | 2026-04-23 |
| CVE-2026-41239 json | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to ver... | Not Provided | 2026-04-23 | 2026-04-23 |
| CVE-2026-41238 json | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable... | Not Provided | 2026-04-23 | 2026-04-23 |
| CVE-2026-41200 json | STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Informatio... | Not Provided | 2026-04-23 | 2026-04-23 |
| CVE-2026-41063 json | WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSafeWit... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-41061 json | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/video.php... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-40928 json | WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/` acc... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-40925 json | WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also routed... | Not Provided | 2026-04-21 | 2026-04-21 |