Products: 4
    Vulnerabilities: 18
    Known Exploited: 0
    0
    Critical Level Threats
    4
    High Level Threats
    12
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-25436

    A cross-site scripting (XSS) vulnerability in the Production module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function.

    Last Modified: Mar 28, 2025
    Published: Mar 01, 2024

    CVE-2023-47271

    PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML document (used for the native import/export plugin) is an image file, before trying to use it for an issue cover image.

    Last Modified: Nov 26, 2024
    Published: Nov 05, 2023

    CVE-2023-5904

    Cross-site Scripting (XSS) - Stored in pkp/pkp-lib

    Last Modified: Feb 27, 2025
    Published: Nov 01, 2023

    CVE-2023-5903

    Cross-site Scripting (XSS) - Stored in pkp/pkp-lib

    Last Modified: Feb 27, 2025
    Published: Nov 01, 2023

    CVE-2023-5900

    Cross-Site Request Forgery in pkp/pkp-lib

    Last Modified: Dec 03, 2024
    Published: Nov 01, 2023
    Items Per Page
    Sfu Vulnerabilities & Security CVEs | CVE-DB