CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header. | 5.4 |
Medium |
||
Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents. | 5.4 |
Medium |
||
In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS. | 6.1 |
Medium |
||
Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors. | 6.1 |
Medium |