Autore: Angelo Barbosa

CVE-2025-23207 | KaTeX up to 0.16.20 Mathematical Expression renderToString cross site scripting (GHSA-cg87-wmx4-v546)

A vulnerability classified as problematic was found in KaTeX up to 0.16.20. Affected by this vulnerability is the function renderToString of the component Mathematical Expression Handler. The manipulation leads to cross site scripting. This vulnerability is known as CVE-2025-23207. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2025-23202 | devycreates Bible-Module up to 0.0.2 FetchVerse/FetchPassage injection

A vulnerability was found in devycreates Bible-Module up to 0.0.2. It has been classified as critical. This affects the function FetchVerse/FetchPassage. The manipulation leads to injection. This vulnerability is uniquely identified as CVE-2025-23202. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più