Show filters
26 Total Results
Displaying 1-10 of 26
Sort by:
Attacker Value
Unknown
CVE-2024-22559
Disclosure Date: January 29, 2024 (last updated February 02, 2024)
LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field.
0
Attacker Value
Unknown
CVE-2023-27060
Disclosure Date: March 22, 2023 (last updated October 08, 2023)
LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.
0
Attacker Value
Unknown
CVE-2022-33009
Disclosure Date: June 27, 2022 (last updated October 07, 2023)
A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploading a crafted PDF file.
0
Attacker Value
Unknown
CVE-2013-10001
Disclosure Date: May 17, 2022 (last updated October 07, 2023)
A vulnerability was found in HTC One/Sense 4.x. It has been rated as problematic. Affected by this issue is the certification validation of the mail client. An exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2021-27112
Disclosure Date: April 15, 2021 (last updated November 28, 2024)
LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php during the downloading of external images.
0
Attacker Value
Unknown
CVE-2021-3355
Disclosure Date: February 24, 2021 (last updated February 22, 2025)
A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/SensitiveWords.
0
Attacker Value
Unknown
CVE-2019-14452
Disclosure Date: July 31, 2019 (last updated November 27, 2024)
Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
0
Attacker Value
Unknown
CVE-2019-13241
Disclosure Date: July 04, 2019 (last updated November 27, 2024)
FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
0
Attacker Value
Unknown
CVE-2019-13032
Disclosure Date: June 28, 2019 (last updated November 27, 2024)
An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library.
0
Attacker Value
Unknown
CVE-2019-12176
Disclosure Date: June 03, 2019 (last updated November 27, 2024)
Privilege escalation in the "HTC Account Service" and "ViveportDesktopService" in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges to SYSTEM via reconfiguration of either service.
0