Vulnerabilities > Sparksuite

DATE CVE VULNERABILITY TITLE RISK
2024-01-17 CVE-2024-0647 Cross-site Scripting vulnerability in Sparksuite Simplemde
A vulnerability, which was classified as problematic, was found in Sparksuite SimpleMDE up to 1.11.2.
network
low complexity
sparksuite CWE-79
6.1
2018-11-07 CVE-2018-19057 Cross-site Scripting vulnerability in Sparksuite Simplemde 1.11.2
SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters, which is mishandled during construction of an A element.
network
sparksuite CWE-79
4.3