VendorsURI.js Projecturi.jsall versions
Vulnerabilities

URI.js Project URI.js

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2022-0868
Open Redirect in medialize/uri.js
Published 2022-03-06 · Modified
8.0EPSS 0.007
CVE-2021-27516
URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
Published 2021-02-21 · Modified
7.5EPSS 0.025
CVE-2022-1243
CRHTLF can lead to invalid protocol extraction potentially leading to XSS in medialize/uri.js
Published 2022-04-05 · Modified
7.2EPSS 0.007
CVE-2020-26291
Hostname spoofing in URI.js
Published 2020-12-30 · Modified
6.5EPSS 0.017
CVE-2022-0613
Authorization Bypass Through User-Controlled Key in medialize/uri.js
Published 2022-02-16 · Modified
6.5EPSS 0.016
CVE-2022-1233
URL Confusion When Scheme Not Supplied in medialize/uri.js
Published 2022-04-04 · Modified
6.5EPSS 0.008
CVE-2021-3647
Open Redirect in medialize/URI.js
Published 2021-07-16 · Modified
6.1EPSS 0.009
CVE-2022-24723
Improper Input Validation in URI.js
Published 2022-03-03 · Modified
5.3EPSS 0.020