Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2127-1 | dojo security update |
EUVD |
EUVD-2020-0309 | dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them. |
Github GHSA |
GHSA-pg97-ww7h-5mjr | XSS in dojox due to insufficient escape in dojox.xmpp.util.xmlEncode |
Ubuntu USN |
USN-7569-1 | Dojo vulnerabilities |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-08-04T22:32:01.603Z
Reserved: 2019-04-03T00:00:00.000Z
Link: CVE-2019-10785
No data.
Status : Modified
Published: 2020-02-13T17:15:29.477
Modified: 2026-06-17T02:11:40.140
Link: CVE-2019-10785
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Debian DLA
EUVD
Github GHSA
Ubuntu USN