Vulnerabilities > Eclipse > Theia > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-11-10 CVE-2021-41038 Unspecified vulnerability in Eclipse Theia
In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().
network
low complexity
eclipse
6.1
2021-03-12 CVE-2021-28162 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Eclipse Theia
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.
network
low complexity
eclipse CWE-829
6.1
2021-03-12 CVE-2021-28161 Cross-site Scripting vulnerability in Eclipse Theia
In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.
network
low complexity
eclipse CWE-79
6.1