Vulnerabilities (CVE)

Filtered by vendor Buttle Project Subscribe
Filtered by product Buttle
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-5422 1 Buttle Project 1 Buttle 2024-02-28 4.3 MEDIUM 6.1 MEDIUM
XSS in buttle npm package version 0.2.0 causes execution of attacker-provided code in the victim's browser when an attacker creates an arbitrary file on the server.
CVE-2018-3766 1 Buttle Project 1 Buttle 2024-02-28 5.0 MEDIUM 7.5 HIGH
Path traversal in buttle module versions <= 0.2.0 allows to read any file in the server.