VendorsNoderednode-redany version
Vulnerabilities

Nodered Node-red any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2021-21297
Prototype Pollution in Node-Red
Published 2021-02-26 · Modified
7.7EPSS 0.014
CVE-2021-21298
Path traversal in Node-Red
Published 2021-02-26 · Modified
6.5EPSS 0.011
CVE-2019-15607
A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc.
Published 2020-01-28 · Modified
5.4EPSS 0.006