All 4 CVE vulnerabilities found in Factor, with AI-generated Chinese analysis, references, and POCs.
Vendor: FactorJS
| CVE ID | Title | CVSS | Severity | Paused |
|---|---|---|---|---|
| CVE-2021-25985 | FactorJS - Insufficient Session Expiration Leads to a Local Account Takeover CWE-613 | 7.8 | High | 2021-11-16 |
| CVE-2021-25984 | FactorJS - Stored Cross-Site Scripting (XSS) in Post Reply Functionality CWE-79 | 6.1 | Medium | 2021-11-16 |
| CVE-2021-25983 | FactorJS - Reflected Cross-Site Scripting (XSS) in Tags and Categories Functionality CWE-79 | 6.1 | Medium | 2021-11-16 |
| CVE-2021-25982 | FactorJS - Reflected Cross-Site Scripting (XSS) in Search Functionality CWE-79 | 6.1 | Medium | 2021-11-16 |
All 4 known CVE vulnerabilities affecting Factor with full Chinese analysis, references, and POCs where available.