Vulnerabilities > Laborator > Neon > 2.0

DATE CVE VULNERABILITY TITLE RISK
2020-06-06 CVE-2020-13890 Cross-site Scripting vulnerability in Laborator Neon 2.0/3.0
The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.
network
laborator CWE-79
3.5
2019-12-30 CVE-2019-20141 Cross-site Scripting vulnerability in Laborator Neon 2.0
An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter.
network
low complexity
laborator CWE-79
6.1