Show filters
5,502 Total Results
Displaying 191-200 of 5,502
Sort by:
Attacker Value
Unknown

CVE-2024-41444

Disclosure Date: August 26, 2024 (last updated September 06, 2024)
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.
Attacker Value
Unknown

CVE-2024-8145

Disclosure Date: August 25, 2024 (last updated September 19, 2024)
A vulnerability, which was classified as problematic, has been found in ClassCMS 4.8. Affected by this issue is some unknown functionality of the file /index.php/admin of the component Article Handler. The manipulation of the argument Title leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-8144

Disclosure Date: August 25, 2024 (last updated September 19, 2024)
A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Logo Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-42939

Disclosure Date: August 21, 2024 (last updated August 31, 2024)
A cross-site scripting (XSS) vulnerability in the component /index/index.html of YZNCMS v1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the configured remarks text field.
Attacker Value
Unknown

CVE-2024-40743

Disclosure Date: August 20, 2024 (last updated August 21, 2024)
The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
0
Attacker Value
Unknown

CVE-2024-27187

Disclosure Date: August 20, 2024 (last updated August 21, 2024)
Improper Access Controls allows backend users to overwrite their username when disallowed.
0
Attacker Value
Unknown

CVE-2024-27186

Disclosure Date: August 20, 2024 (last updated August 21, 2024)
The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
0
Attacker Value
Unknown

CVE-2024-27185

Disclosure Date: August 20, 2024 (last updated August 21, 2024)
The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.
0
Attacker Value
Unknown

CVE-2024-27184

Disclosure Date: August 20, 2024 (last updated August 21, 2024)
Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..
0
Attacker Value
Unknown

CVE-2024-43377

Disclosure Date: August 20, 2024 (last updated August 27, 2024)
Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1.2.