Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Leonabcd123

#20521of 53,630
12.5Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2025-49173
7.1
2025-12-04
Unknown · Monkeytype · CVE-2025-66563
**Name of the Vulnerable Software and Affected Versions** Monkeytype versions prior to 25.49.0 **Description** The software exhibits improper handling of user input, potentially allowing an attacker to execute malicious JavaScript code on users who view a malicious quote submission. The `quote.text` and `quote.source` inputs are directly inserted into the Document Object Model (DOM) without sufficient sanitization. This allows HTML tags within these inputs to be rendered, potentially leading to cross-site scripting (XSS). **Recommendations** Versions prior to 25.49.0 should be updated.
PT-2025-39404
5.4
2025-09-25
Unknown · Monkeytype · CVE-2025-59838
**Name of the Vulnerable Software and Affected Versions** Monkeytype versions prior to 25.36.0 **Description** Improper handling of user input when loading a saved custom text can lead to cross-site scripting (XSS). **Recommendations** Update to a version later than 25.36.0.