Show filters
5,502 Total Results
Displaying 191-200 of 5,502
Sort by:
Attacker Value
Unknown
CVE-2024-41444
Disclosure Date: August 26, 2024 (last updated September 06, 2024)
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.
0
Attacker Value
Unknown
CVE-2024-8145
Disclosure Date: August 25, 2024 (last updated September 19, 2024)
A vulnerability, which was classified as problematic, has been found in ClassCMS 4.8. Affected by this issue is some unknown functionality of the file /index.php/admin of the component Article Handler. The manipulation of the argument Title leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-8144
Disclosure Date: August 25, 2024 (last updated September 19, 2024)
A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Logo Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-42939
Disclosure Date: August 21, 2024 (last updated August 31, 2024)
A cross-site scripting (XSS) vulnerability in the component /index/index.html of YZNCMS v1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the configured remarks text field.
0
Attacker Value
Unknown
CVE-2024-40743
Disclosure Date: August 20, 2024 (last updated August 21, 2024)
The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
0
Attacker Value
Unknown
CVE-2024-27187
Disclosure Date: August 20, 2024 (last updated August 21, 2024)
Improper Access Controls allows backend users to overwrite their username when disallowed.
0
Attacker Value
Unknown
CVE-2024-27186
Disclosure Date: August 20, 2024 (last updated August 21, 2024)
The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
0
Attacker Value
Unknown
CVE-2024-27185
Disclosure Date: August 20, 2024 (last updated August 21, 2024)
The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.
0
Attacker Value
Unknown
CVE-2024-27184
Disclosure Date: August 20, 2024 (last updated August 21, 2024)
Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..
0
Attacker Value
Unknown
CVE-2024-43377
Disclosure Date: August 20, 2024 (last updated August 27, 2024)
Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1.2.
0