Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2024-13700

Disclosure Date: January 30, 2025 (last updated February 01, 2025)
The Embed Swagger UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsgui' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-22207

Disclosure Date: January 15, 2024 (last updated January 24, 2024)
fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served by the module. The vulnerability is fixed in v2.1.0. Setting the `baseDir` option can also work around this vulnerability.
Attacker Value
Unknown

CVE-2021-46708

Disclosure Date: March 11, 2022 (last updated October 07, 2023)
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
Attacker Value
Unknown

CVE-2018-25031

Disclosure Date: March 11, 2022 (last updated July 17, 2024)
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.
Attacker Value
Unknown

CVE-2016-1000229

Disclosure Date: December 20, 2019 (last updated November 27, 2024)
swagger-ui has XSS in key names
Attacker Value
Unknown

CVE-2019-17495

Disclosure Date: October 10, 2019 (last updated November 08, 2023)
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method.
Attacker Value
Unknown

CVE-2016-5682

Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.