Releases94
Frequency4 weeks 21 hours
Last Release
Stars2.24K
A fast, simple & powerful comment system.

CVE History

CVEPublishedCVSS v3CVSS v2
9.6 CRITICAL

Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.

5.4 MEDIUM3.5 LOW

Cross Site Scripting (XSS) vulnerability in xCss Valine v1.4.14 via the nick parameter to /classes/Comment.

5.3 MEDIUM5 MEDIUM

Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agent) value that only specifies the product and version.

6.1 MEDIUM4.3 MEDIUM

An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.