Known Vulnerabilities for products from Dradisframework
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Dradisframework".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-31223 json | Dradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars. | 5.4 - MEDIUM | 2023-04-25 | 2023-05-11 |
| CVE-2022-30028 json | Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token. | 5.9 - MEDIUM | 2022-06-24 | 2022-07-01 |
| CVE-2019-19946 json | The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the project... | 6.5 - MEDIUM | 2020-03-16 | 2021-07-21 |
| CVE-2019-5925 json | Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professi... | 5.4 - MEDIUM | 2019-03-12 | 2019-03-13 |
Known software with vulnerabilities from Dradisframework
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Dradisframework | Dradis | 2.0.0 |