Vulnerabilities (CVE)

Filtered by vendor Evilmartians Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-1496 1 Evilmartians 1 Imgproxy 2024-02-28 N/A 5.4 MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0.
CVE-2023-30019 1 Evilmartians 1 Imgproxy 2024-02-28 N/A 5.3 MEDIUM
imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.