Vulnerabilities > Opencollective

DATE CVE VULNERABILITY TITLE RISK
2023-01-14 CVE-2023-0300 Cross-site Scripting vulnerability in Opencollective Alf.Io
Cross-site Scripting (XSS) - Reflected in GitHub repository alfio-event/alf.io prior to 2.0-M4-2301.
network
low complexity
opencollective CWE-79
5.4
2023-01-14 CVE-2023-0301 Cross-site Scripting vulnerability in Opencollective Alf.Io
Cross-site Scripting (XSS) - Stored in GitHub repository alfio-event/alf.io prior to Alf.io 2.0-M4-2301.
network
low complexity
opencollective CWE-79
5.4