Prototypejs Prototype vulnerabilities
3 known vulnerabilities affecting prototypejs/prototype.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-27511HIGHCVSS 7.5v1.7.32021-06-21
CVE-2020-27511 [HIGH] CVE-2020-27511: An issue was discovered in the stripTags and unescapeHTML components in Prototype 1.7.3 where an att
An issue was discovered in the stripTags and unescapeHTML components in Prototype 1.7.3 where an attacker can cause a Regular Expression Denial of Service (ReDOS) through stripping crafted HTML tags.
nvd
CVE-2020-7993MEDIUMCVSS 4.3v1.6.0.12020-02-03
CVE-2020-7993 [MEDIUM] CWE-862 CVE-2020-7993: Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other use
Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field.
nvd
CVE-2008-7220HIGHCVSS 7.5fixed in 1.6.0.22009-09-13
CVE-2008-7220 [HIGH] CVE-2008-7220: Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows atta
Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors.
nvd