Vulnerabilities (CVE)

Filtered by vendor Sync Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-26559 1 Sync 2 Oxygen Content Fusion, Oxygen Xml Web Author 2024-11-21 N/A 5.3 MEDIUM
A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2023022015 allows an attacker to read files from a WEB-INF directory via a crafted HTTP request. (XML Web Author 24.1.0.3 build 2023021714 and 23.1.1.4 build 2023021715 are also fixed versions.)
CVE-2021-46827 1 Sync 5 Oxygen Publishing Engine, Oxygen Xml Author, Oxygen Xml Developer and 2 more 2024-11-21 N/A 6.1 MEDIUM
An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated using Oxygen XML WebHelp) allows attackers to execute JavaScript by convincing a user to type specific text in the WebHelp output search field.
CVE-2019-20191 1 Sync 3 Oxygen Xml Author, Oxygen Xml Developer, Oxygen Xml Editor 2024-11-21 5.0 MEDIUM 7.5 HIGH
Oxygen XML Editor 21.1.1 allows XXE to read any file.