Vulnerabilities > IF ME > Ifme > 3.4.1

DATE CVE VULNERABILITY TITLE RISK
2021-12-29 CVE-2021-25988 Cross-site Scripting vulnerability in If-Me Ifme
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin.
network
low complexity
if-me CWE-79
5.4
2021-12-29 CVE-2021-25989 Cross-site Scripting vulnerability in If-Me Ifme
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor.
network
low complexity
if-me CWE-79
5.4