CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
panel/login in Kirby v2.5.12 allows XSS via a blog name.
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name.
index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.
Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown.
Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) discription or (2) comments field, related to users/userAddContent.
Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.
Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control.
