Show filters
51 Total Results
Displaying 31-40 of 51
Sort by:
Attacker Value
Unknown
CVE-2022-37250
Disclosure Date: September 16, 2022 (last updated October 08, 2023)
Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.
0
Attacker Value
Unknown
CVE-2022-29933
Disclosure Date: May 09, 2022 (last updated October 07, 2023)
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the password reset functionality. Specifically, the attacker must send X-Forwarded-Host to the /index.php?p=admin/actions/users/send-password-reset-email URI. NOTE: the vendor's position is that a customer can already work around this by adjusting the configuration (i.e., by not using the default configuration).
0
Attacker Value
Unknown
CVE-2022-28378
Disclosure Date: April 03, 2022 (last updated October 07, 2023)
Craft CMS before 3.7.29 allows XSS.
0
Attacker Value
Unknown
CVE-2021-41824
Disclosure Date: September 30, 2021 (last updated February 23, 2025)
Craft CMS before 3.7.14 allows CSV injection.
0
Attacker Value
Unknown
CVE-2021-27902
Disclosure Date: June 30, 2021 (last updated February 22, 2025)
An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.
0
Attacker Value
Unknown
CVE-2021-27903
Disclosure Date: June 30, 2021 (last updated February 22, 2025)
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).
0
Attacker Value
Unknown
CVE-2021-32470
Disclosure Date: May 07, 2021 (last updated February 22, 2025)
Craft CMS before 3.6.13 has an XSS vulnerability.
0
Attacker Value
Unknown
CVE-2020-19626
Disclosure Date: March 26, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new.
0
Attacker Value
Unknown
CVE-2019-9554
Disclosure Date: December 31, 2019 (last updated November 27, 2024)
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.
0
Attacker Value
Unknown
CVE-2019-15929
Disclosure Date: October 24, 2019 (last updated November 27, 2024)
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
0