Known Vulnerabilities for products from Etherpad
Listed below are 19 of the newest known vulnerabilities associated with the vendor "Etherpad".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-43802 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2021-12-09 | 2023-08-31 |
| CVE-2021-34817 json | A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaS... | 6.1 - MEDIUM | 2021-07-19 | 2021-07-27 |
| CVE-2021-34816 json | An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on ... | 7.2 - HIGH | 2021-07-21 | 2021-07-30 |
| CVE-2020-22785 json | Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad... | 7.5 - HIGH | 2021-04-28 | 2021-05-05 |
| CVE-2020-22784 json | In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving d... | 7.5 - HIGH | 2021-04-28 | 2022-07-12 |
| CVE-2020-22783 json | Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database backe... | 6.5 - MEDIUM | 2021-04-28 | 2021-05-05 |
| CVE-2020-22782 json | Etherpad < 1.8.3 is affected by a denial of service in the import functionality. Upload of binary file to the import endpoint... | 7.5 - HIGH | 2021-04-28 | 2021-05-05 |
| CVE-2020-22781 json | In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of ... | 7.5 - HIGH | 2021-04-28 | 2021-05-05 |
| CVE-2019-18209 json | templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by In... | 6.1 - MEDIUM | 2019-10-19 | 2019-10-22 |
| CVE-2018-9845 json | Etherpad Lite before 1.6.4 is exploitable for admin access. | 9.8 - CRITICAL | 2018-04-29 | 2019-10-03 |
| CVE-2018-9327 json | Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be conf... | 8.1 - HIGH | 2018-04-07 | 2018-05-11 |
| CVE-2018-9326 json | Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code. | 9.8 - CRITICAL | 2018-04-07 | 2018-05-11 |
| CVE-2018-9325 json | Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of ... | 7.5 - HIGH | 2018-04-07 | 2018-05-11 |
| CVE-2018-6835 json | node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass inten... | 9.8 - CRITICAL | 2018-02-08 | 2019-10-03 |
| CVE-2018-6834 json | static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href. | 6.1 - MEDIUM | 2018-02-08 | 2018-02-26 |
| CVE-2015-4085 json | Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1. | 7.5 - HIGH | 2017-09-07 | 2017-09-18 |
| CVE-2015-3309 json | Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arb... | 7.5 - HIGH | 2020-02-13 | 2020-02-19 |
| CVE-2015-3297 json | Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arb... | Not Provided | 2017-07-07 | 2025-04-20 |
| CVE-2015-2298 json | node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by l... | 7.5 - HIGH | 2018-01-12 | 2018-01-29 |
Known software with vulnerabilities from Etherpad
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Etherpad | Etherpad | 1.0 |