Livejournal is a social-networking and blogging platform with a focused vulnerability footprint concentrated in its core service offering. The limited disclosure record reflects the product's narrower attack surface relative to mainstream infrastructure vendors; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Livejournal over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0310MEDIUM Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semico | Nov 23, 2004 | 6.8 | 23 | NO | NO |
CVE-2005-4454MEDIUM Validate-before-filter vulnerability in cleanhtml.pl 1.129 in LiveJournal CVS before Dec 7 2005, when the cleancss option is enabled, allows remote attackers to conduct cross-site | Dec 21, 2005 | 4.3 | 21 | NO | YES |
CVE-2005-4455MEDIUM cleanhtml.pl 1.129 in LiveJournal CVS before Dec 13 2005 allows remote attackers to inject scripting languages via the XSL namespace in XML, via vectors such as customview.cgi. | Dec 21, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Livejournal.
Media articles that mention a CVE ID that affects a product developed by Livejournal — matched by CVE ID, not by vendor name.