Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2024-13700
Disclosure Date: January 30, 2025 (last updated February 01, 2025)
The Embed Swagger UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsgui' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-22207
Disclosure Date: January 15, 2024 (last updated January 24, 2024)
fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served by the module. The vulnerability is fixed in v2.1.0. Setting the `baseDir` option can also work around this vulnerability.
0
Attacker Value
Unknown
CVE-2021-46708
Disclosure Date: March 11, 2022 (last updated October 07, 2023)
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
0
Attacker Value
Unknown
CVE-2018-25031
Disclosure Date: March 11, 2022 (last updated July 17, 2024)
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.
0
Attacker Value
Unknown
CVE-2016-1000229
Disclosure Date: December 20, 2019 (last updated November 27, 2024)
swagger-ui has XSS in key names
0
Attacker Value
Unknown
CVE-2019-17495
Disclosure Date: October 10, 2019 (last updated November 08, 2023)
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method.
0
Attacker Value
Unknown
CVE-2016-5682
Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
0