Vulnerabilities > Mycolorway

DATE CVE VULNERABILITY TITLE RISK
2019-05-13 CVE-2018-19048 Cross-site Scripting vulnerability in Mycolorway Simditor
Simditor through 2.3.21 allows DOM XSS via an onload attribute within a malformed SVG element.
network
mycolorway CWE-79
4.3
2018-01-31 CVE-2018-6464 Cross-site Scripting vulnerability in Mycolorway Simditor 2.3.11
Simditor v2.3.11 allows XSS via crafted use of svg/onload=alert in a TEXTAREA element, as demonstrated by Firefox 54.0.1.
network
mycolorway CWE-79
4.3