Lucene search

K

Highlight Security Vulnerabilities

cve
cve

CVE-2023-33187

Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when a password html input is switched to type="text" via a javascript "Show Password" button. This differs from the expected behavior which always obfuscates type="password" inputs.....

6.5CVSS

6.4AI Score

0.001EPSS

2023-05-26 09:15 PM
34
cve
cve

CVE-2022-3462

The Highlight Focus WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite...

4.8CVSS

4.7AI Score

0.001EPSS

2022-11-07 10:15 AM
26
7