Vulnerabilities > Magicpin

DATE CVE VULNERABILITY TITLE RISK
2022-06-14 CVE-2022-31447 XXE vulnerability in Magicpin 3.4
An XML external entity (XXE) injection vulnerability in Magicpin v3.4 allows attackers to access sensitive database information via a crafted SVG file.
network
low complexity
magicpin CWE-611
7.5
2020-11-23 CVE-2020-28927 Cross-site Scripting vulnerability in Magicpin 2.1
There is a Stored XSS in Magicpin v2.1 in the User Registration section.
network
low complexity
magicpin CWE-79
6.1