Search CVE reports


Toggle filters

1 – 10 of 14 results


CVE-2021-23450

Medium priority

Some fixes available 3 of 9

All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

1 affected package

dojo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dojo Not affected Fixed Fixed Vulnerable
Show less packages

CVE-2020-5259

Medium priority
Needs evaluation

In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such...

1 affected package

dojo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dojo Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-5258

Medium priority
Needs evaluation

In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as...

1 affected package

dojo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dojo Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2020-4051

Medium priority

Some fixes available 2 of 10

In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8, and greater than or equal to 1.14.0 and less than 1.14.7, and greater than or...

1 affected package

dojo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dojo Not affected Not affected Fixed Vulnerable
Show less packages

CVE-2019-10785

Medium priority

Some fixes available 2 of 10

dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them.

1 affected package

dojo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dojo Not affected Not affected Fixed Vulnerable
Show less packages

CVE-2018-6561

Medium priority
Vulnerable

dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.

1 affected package

dojo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dojo Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2018-15494

Medium priority

Some fixes available 1 of 11

In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.

1 affected package

dojo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dojo Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-1000665

Low priority
Needs evaluation

Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in...

1 affected package

dojo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dojo Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2015-5654

Medium priority
Not affected

Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1 affected package

dojo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dojo
Show less packages

CVE-2010-2276

Negligible priority
Not affected

The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 has the copyTests=true and mini=false options, which...

1 affected package

dojo

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dojo
Show less packages