Vulnerabilities > Ipandao

DATE CVE VULNERABILITY TITLE RISK
2023-05-08 CVE-2020-19660 Cross-site Scripting vulnerability in Ipandao Editor.Md 1.5.0
Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url values.
network
low complexity
ipandao CWE-79
6.1
2023-05-01 CVE-2023-29641 Cross-site Scripting vulnerability in Ipandao Editor.Md
Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script or HTML via crafted markdown text.
network
low complexity
ipandao CWE-79
6.1
2019-08-03 CVE-2019-14653 Cross-site Scripting vulnerability in Ipandao Editor.Md 1.5.0
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
network
ipandao CWE-79
4.3
2019-03-13 CVE-2019-9737 Cross-site Scripting vulnerability in Ipandao Editor.Md 1.5.0
Editor.md 1.5.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
network
ipandao CWE-79
4.3
2018-11-07 CVE-2018-19056 Cross-site Scripting vulnerability in Ipandao Editor.Md 1.5.0
pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element.
network
ipandao CWE-79
4.3
2018-09-02 CVE-2018-16330 Cross-site Scripting vulnerability in Ipandao Editor.Md 1.5.0
Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.
network
ipandao CWE-79
4.3