ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-19048
Simditor through 2.3.21 allows DOM XSS via an onload attribute within a malformed SVG element.

Simditor through 2.3.21 allows DOM XSS via an onload attribute within a malformed SVG element.

NVD description · AI analysis pending
6.12% PoC ×2
  • mycolorway simditor
CVE-2018-6464
Simditor v2.3.11 allows XSS via crafted use of svg/onload=alert in a TEXTAREA element, as demonstrated by Firefox 54.0.1.

Simditor v2.3.11 allows XSS via crafted use of svg/onload=alert in a TEXTAREA element, as demonstrated by Firefox 54.0.1.

NVD description · AI analysis pending
6.1<1% PoC
  • mycolorway simditor