Skip to main content

Vendor archive

camunda CVEs

Beta · best-effort

3 CVEs tagged to vendor camunda1 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2024-51577

Published Nov 10, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in neville.lugton bpmn.io bpmnio allows Stored XSS.This issue affects bpmn.io: f…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23460

Published Jan 21, 2022

The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28154

Published Mar 11, 2021

Camunda Modeler (aka camunda-modeler) through 4.6.0 allows arbitrary file access. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interf…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1