© 2025-2026 PySpect
First version without a known vulnerability: 4.14.0
NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0.
Fixed in: 023a0d52f106321838ab1c0997e76693f4dcbdf6, 4.14.0
Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-urlencoded, multipart/form-data, and text/plain.
Fixed in: 4.0.0