• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2019-17609

February 26, 2023 by

HongCMS 3.0.0 has XSS via the install/index.php dbusername parameter.

CVE-2019-17610

February 26, 2023 by

HongCMS 3.0.0 has XSS via the install/index.php dbpassword parameter.

CVE-2019-17611

February 26, 2023 by

HongCMS 3.0.0 has XSS via the install/index.php tableprefix parameter.

CVE-2019-17625

February 26, 2023 by

There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for Node.js and Electron, such as an exec of OS commands within the onerror attribute of an IMG element.

CVE-2019-17629

February 26, 2023 by

CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the “file manager > upload images” screen.

CVE-2019-17630

February 26, 2023 by

CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the “News > Add Article” screen.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1095
  • Go to page 1096
  • Go to page 1097
  • Go to page 1098
  • Go to page 1099
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE