CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

gnome

epiphany

9 known vulnerabilities · sorted by CVSS score

CVE-2019-6251
HIGH8.1

WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.

gnome / epiphany+9
Network
Published Jan 14, 2019
CVE-2018-12016
HIGH7.5

libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain window.open and document.write calls.

gnome / epiphany
Network
Published Jun 7, 2018
CVE-2018-11396
HIGH7.5

ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open call.

gnome / epiphany
Network
Published May 23, 2018
CVE-2022-29536
HIGH7.5

In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.

gnome / epiphany+6
Network
Published Apr 20, 2022
CVE-2023-26081
HIGH7.5

In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.

gnome / epiphany+1
Network
Published Feb 20, 2023
CVE-2021-45085
MEDIUM6.1

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.

gnome / epiphany+3
Network
Published Dec 16, 2021
CVE-2021-45088
MEDIUM6.1

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.

gnome / epiphany+3
Network
Published Dec 16, 2021
CVE-2021-45087
MEDIUM6.1

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.

gnome / epiphany+3
Network
Published Dec 16, 2021
CVE-2021-45086
MEDIUM6.1

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.

gnome / epiphany+2
Network
Published Dec 16, 2021