Vulnerabilities (CVE)

Filtered by vendor Ragic Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-41343 1 Ragic 1 Enterprise Cloud Database 2023-11-09 N/A 5.4 MEDIUM
Rogic No-Code Database Builder's file uploading function has insufficient filtering for special characters. A remote attacker with regular user privilege can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack.
CVE-2022-40739 1 Ragic 1 Ragic 2022-10-31 N/A 5.4 MEDIUM
Ragic report generation page has insufficient filtering for special characters. A remote attacker with general user privilege can inject JavaScript to perform XSS (Reflected Cross-Site Scripting) attack.