Show filters
102 Total Results
Displaying 31-40 of 102
Sort by:
Attacker Value
Unknown

CVE-2020-18875

Disclosure Date: August 18, 2021 (last updated February 23, 2025)
Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files.
Attacker Value
Unknown

CVE-2020-18456

Disclosure Date: August 12, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php.
Attacker Value
Unknown

CVE-2021-35361

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
A reflected cross site scripting (XSS) vulnerability in dotAdmin/#/c/links of dotCMS 21.05.1 allows attackers to execute arbitrary commands or HTML via a crafted payload.
Attacker Value
Unknown

CVE-2021-35360

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
A reflected cross site scripting (XSS) vulnerability in dotAdmin/#/c/containers of dotCMS 21.05.1 allows attackers to execute arbitrary commands or HTML via a crafted payload.
Attacker Value
Unknown

CVE-2021-35358

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
A stored cross site scripting (XSS) vulnerability in dotAdmin/#/c/c_Images of dotCMS 21.05.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' and 'Filename' parameters.
Attacker Value
Unknown

CVE-2020-22535

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php.
Attacker Value
Unknown

CVE-2020-23580

Disclosure Date: July 08, 2021 (last updated November 28, 2024)
Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.
Attacker Value
Unknown

CVE-2020-20363

Disclosure Date: July 08, 2021 (last updated February 23, 2025)
Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.
Attacker Value
Unknown

CVE-2020-21003

Disclosure Date: June 03, 2021 (last updated February 22, 2025)
Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php.
Attacker Value
Unknown

CVE-2020-17542

Disclosure Date: April 23, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail" comment window of the "/dotAdmin/#/c/workflow" component.