CVE-2024-53272
- EPSS 0.09%
- Veröffentlicht 12.12.2024 02:15:28
- Zuletzt bearbeitet 05.09.2025 21:38:03
Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `login` and `social media` function in `RegisterLoginReset.vue` contains two reflected XSS vulnerabilities due to an inc...
CVE-2024-53273
- EPSS 0.09%
- Veröffentlicht 12.12.2024 02:15:28
- Zuletzt bearbeitet 05.09.2025 21:38:01
Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `RegisterLoginReset.vue` contains a reflected XSS vulnerability due to an incorrect sanitization ...
CVE-2024-53274
- EPSS 0.09%
- Veröffentlicht 12.12.2024 02:15:28
- Zuletzt bearbeitet 05.09.2025 21:37:59
Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `home.vue` containsa reflected XSS vulnerability due to an incorrect sanitization function. An at...
CVE-2022-23078
- EPSS 0.2%
- Veröffentlicht 22.06.2022 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:47:56
In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.
CVE-2022-23077
- EPSS 0.24%
- Veröffentlicht 22.06.2022 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:47:55
In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.