Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2025-23650

Disclosure Date: February 14, 2025 (last updated February 15, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in razvypp Tidy.ro allows Reflected XSS. This issue affects Tidy.ro: from n/a through 1.3.
0
Attacker Value
Unknown

CVE-2024-56015

Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in John Godley Tidy Up allows Reflected XSS.This issue affects Tidy Up: from n/a through 1.3.
0
Attacker Value
Unknown

CVE-2024-9357

Disclosure Date: November 12, 2024 (last updated November 12, 2024)
The xili-tidy-tags plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 1.12.04 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2023-34623

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
An issue was discovered jtidy thru r938 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
Attacker Value
Unknown

CVE-2022-47448

Disclosure Date: May 24, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in dev.Xiligroup.Com - MS plugin <= 1.12.03 versions.
Attacker Value
Unknown

CVE-2021-33391

Disclosure Date: February 17, 2023 (last updated October 08, 2023)
An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.
Attacker Value
Unknown

CVE-2017-17497

Disclosure Date: December 10, 2017 (last updated November 26, 2024)
In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because the currentNode variable in the "children of the head" processing feature is modified in the loop without validating the new value.
Attacker Value
Unknown

CVE-2014-2277

Disclosure Date: October 17, 2017 (last updated November 26, 2024)
The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpnam function.
Attacker Value
Unknown

CVE-2017-13692

Disclosure Date: August 25, 2017 (last updated November 26, 2024)
In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as demonstrated by an invalid ISALNUM argument.
0
Attacker Value
Unknown

CVE-2016-10374

Disclosure Date: May 17, 2017 (last updated November 26, 2024)
perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current working directory for certain output files and does not have a symlink-attack protection mechanism, which allows local users to overwrite arbitrary files by creating a symlink, as demonstrated by creating a perltidy.ERR symlink that the victim cannot delete.