Vulnerabilities (CVE)

Filtered by vendor Newphoria Corporation Subscribe
Filtered by product Applican
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-5632 1 Newphoria Corporation 1 Applican 2023-12-10 6.8 MEDIUM N/A
The runtime engine in the Newphoria applican framework before 1.12.3 for Android and before 1.12.2 for iOS allows attackers to bypass a whitelist.xml URL whitelist protection mechanism and obtain API access via unspecified vectors.
CVE-2015-7772 1 Newphoria Corporation 1 Applican 2023-12-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for Android and iOS allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers WebView anchor attachment in an applican application, a different vulnerability than CVE-2015-7771.
CVE-2015-7771 1 Newphoria Corporation 1 Applican 2023-12-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for Android and iOS allows remote attackers to inject arbitrary web script or HTML via a crafted SSID that is encountered by an applican application, a different vulnerability than CVE-2015-7772.