Storytlr is a personal lifestreaming and content aggregation platform with a narrowly scoped product footprint, and its observed vulnerabilities center on cross-site scripting issues arising from improper input neutralization during web page generation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Storytlr over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-100038MEDIUM Cross-site scripting (XSS) vulnerability in Storytlr 1.3.dev and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter to search/. | Jan 13, 2015 | 4.3 | 16 | NO | NO |
CVE-2014-100037MEDIUM Cross-site scripting (XSS) vulnerability in Storytlr 1.3.dev and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to archives/. | Jan 13, 2015 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Storytlr.
Media articles that mention a CVE ID that affects a product developed by Storytlr — matched by CVE ID, not by vendor name.