• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2020-12703

February 26, 2023 by

UliCMS before 2020.2 has XSS during PackageController uninstall.

CVE-2020-12704

February 26, 2023 by

UliCMS before 2020.2 has PageController stored XSS.

CVE-2020-12705

February 26, 2023 by

Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.

CVE-2020-12706

February 26, 2023 by

Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_admin.php

CVE-2020-12707

February 26, 2023 by

An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT elements.

CVE-2020-12708

February 26, 2023 by

Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. NOTE: this might overlap CVE-2012-6043.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 903
  • Go to page 904
  • Go to page 905
  • Go to page 906
  • Go to page 907
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE