Vulnerabilities > Conversejs

DATE CVE VULNERABILITY TITLE RISK
2018-02-19 CVE-2018-6591 Information Exposure vulnerability in Conversejs Converse.Js
Converse.js and Inverse.js through 3.3 allow remote attackers to obtain sensitive information because it is too difficult to determine whether safe publication of private data was configured or even intended.
network
low complexity
conversejs CWE-200
5.0
2017-02-09 CVE-2017-5858 Improper Input Validation vulnerability in Conversejs Converse.Js
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display.
network
conversejs CWE-20
4.3