CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Evolution CMS 1.4.x allows XSS via the manager/ search parameter.
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.
Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter.
Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.
Pluck v4.7.7 allows CSRF via admin.php?action=settings.
Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title.
Mezzanine CMS v4.3.1 allows XSS via the /admin/blog/blogcategory/add/?_to_field=id&_popup=1 title parameter at admin/blog/blogpost/add/.
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.
Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.
IBM DataPower Gateways 7.5, 7.5.1, 7.5.2, 7.6, and 2018.4 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 144889.
