Vulnerabilities > Nodered > Node RED > 0.18.7

DATE CVE VULNERABILITY TITLE RISK
2021-02-26 CVE-2021-21298 Path Traversal vulnerability in Nodered Node-Red
Node-Red is a low-code programming for event-driven applications built using nodejs.
network
low complexity
nodered CWE-22
6.5
2021-02-26 CVE-2021-21297 Unspecified vulnerability in Nodered Node-Red
Node-Red is a low-code programming for event-driven applications built using nodejs.
network
low complexity
nodered
6.5
2020-01-28 CVE-2019-15607 Cross-site Scripting vulnerability in Nodered Node-Red
A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things.
network
nodered CWE-79
3.5