Software
dojo
Aggregate across all detected versions
Total Hosts
0
distinct hosts
Versions Seen
0
Countries
0
Known CVEs
13
known CVEs
Top Countries
No geolocated hosts.
Top ASNs
No attributed hosts.
CVE Matches
| CVE | CVSS | Severity | Summary |
|---|---|---|---|
| CVE-2010-2272 | 10.0 | HIGH | Unspecified vulnerability in iframe_history.html in Dojo 0.4.x before 0.4.4 has unknown impact and remote attack vectors. |
| CVE-2010-2276 | 10.0 | HIGH | The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1... |
| CVE-2018-15494 | 9.8 | N/A | In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid. |
| CVE-2020-5258 | 7.7 | N/A | In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject proper... |
| CVE-2021-23450 | 7.5 | N/A | All versions of package dojo are vulnerable to Prototype Pollution via the setObject function. |
| CVE-2018-1000665 | 6.1 | N/A | Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-... |
| CVE-2018-6561 | 6.1 | N/A | dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element. |
| CVE-2007-6726 | 4.3 | MEDIUM | Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbit... |
| CVE-2008-6681 | 4.3 | MEDIUM | Cross-site scripting (XSS) vulnerability in dijit.Editor in Dojo before 1.1 allows remote attackers to inject arbitrary web script or HTML via XML entities in a... |
| CVE-2010-2273 | 4.3 | MEDIUM | Multiple cross-site scripting (XSS) vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4... |
| CVE-2010-2274 | 4.3 | MEDIUM | Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remo... |
| CVE-2010-2275 | 4.3 | MEDIUM | Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script o... |
| CVE-2015-5654 | 4.3 | MEDIUM | Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |