Tom Boutell
9 exploits
Active since Jun 2018
sanitize-html < 1.0.3 - Cross-Site Scripting via Improper Href Attribute Validation
CVSS 6.1
ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API
CVSS 5.3
ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
CVSS 3.7
ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API
CVSS 5.3
ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escaping Style Tag Context
CVSS 5.4
ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
CVSS 8.7
Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field Restrictions
CVSS 5.3
ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements
CVSS 6.1
sanitize-html < 1.11.1 - Cross-Site Scripting via Non-Text Tag Handling
CVSS 6.1