Vulnerabilities (CVE)

Filtered by vendor Onesignal
Angry Yack Logo
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-28430 1 Onesignal 1 React-native-onesignal 2024-11-21 N/A 7.3 HIGH
OneSignal is an email, sms, push notification, and in-app message service for mobile apps.The Zapier.yml workflow is triggered on issues (types: [closed]) (i.e., when an Issue is closed). The workflow starts with full write-permissions GitHub repository token since the default workflow permissions on Organization/Repository level are set to read-write. This workflow runs the following step with data controlled by the comment `(${{ github.event.issue.title }} – the full title of the Issue)`, allo ...

Show More

CVE-2019-15827 1 Onesignal 1 Onesignal-free-web-push-notifications 2024-11-21 3.5 LOW 5.4 MEDIUM
The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.