Known Vulnerabilities for Uri.js by Uri.js Project
Listed below are 8 of the newest known vulnerabilities associated with "Uri.js" by "Uri.js Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-24723 json | URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning ... | 5.3 - MEDIUM | 2022-03-03 | 2023-07-03 |
| CVE-2022-1243 json | CRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to 1.19... | 6.1 - MEDIUM | 2022-04-05 | 2023-07-24 |
| CVE-2022-1233 json | URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11. | 6.1 - MEDIUM | 2022-04-04 | 2022-11-29 |
| CVE-2022-0868 json | Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10. | 6.1 - MEDIUM | 2022-03-06 | 2022-03-11 |
| CVE-2022-0613 json | Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8. | 6.5 - MEDIUM | 2022-02-16 | 2023-11-07 |
| CVE-2021-27516 json | URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative pa... | 7.5 - HIGH | 2021-02-22 | 2022-11-29 |
| CVE-2021-3647 json | URI.js is vulnerable to URL Redirection to Untrusted Site | 6.1 - MEDIUM | 2021-07-16 | 2021-07-28 |
| CVE-2020-26291 json | URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be spoofed... | 6.5 - MEDIUM | 2020-12-31 | 2022-11-29 |