Vulnerabilities > Apache > Pluto > 2.0.0

DATE CVE VULNERABILITY TITLE RISK
2022-01-06 CVE-2021-36737 Cross-site Scripting vulnerability in Apache Pluto
The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks.
network
low complexity
apache CWE-79
6.1
2022-01-06 CVE-2021-36738 Cross-site Scripting vulnerability in Apache Pluto
The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks.
network
low complexity
apache CWE-79
6.1
2020-10-12 CVE-2020-15250 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability.
local
low complexity
junit debian apache oracle CWE-732
5.5