Skip to main content

Vendor archive

prototypejs CVEs

Beta · best-effort

4 CVEs tagged to vendor prototypejs0 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2020-27511

Published Jun 21, 2021

An issue was discovered in the stripTags and unescapeHTML components in Prototype 1.7.3 where an attacker can cause a Regular Expression Denial of Service (ReDOS) through strippin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7993

Published Feb 3, 2020

Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7220

Published Sep 13, 2009

Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-2383

Published Apr 30, 2007

The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attacker…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1