|
211241
|
7.5 |
HIGH
Network
|
s-cms
|
s-cms
|
An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.
|
CWE-611
XXE
|
CVE-2020-19954
|
2024-11-21 14:09 |
2021-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211242
|
8.8 |
HIGH
Network
|
yzmcms
|
yzmcms
|
A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the application.
|
CWE-352
Origin Validation Error
|
CVE-2020-19951
|
2024-11-21 14:09 |
2021-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211243
|
4.8 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
A cross-site scripting (XSS) vulnerability in the /banner/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19950
|
2024-11-21 14:09 |
2021-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211244
|
4.8 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
A cross-site scripting (XSS) vulnerability in the /link/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19949
|
2024-11-21 14:09 |
2021-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211245
|
6.1 |
MEDIUM
Network
|
manageengine
|
opmanager
|
Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19554
|
2024-11-21 14:09 |
2021-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211246
|
5.4 |
MEDIUM
Network
|
wuzhicms
|
wuzhicms
|
Cross Site Scripting (XSS) vlnerability exists in WUZHI CMS up to and including 4.1.0 in the config function in coreframe/app/attachment/libs/class/ckditor.class.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19553
|
2024-11-21 14:09 |
2021-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211247
|
8.8 |
HIGH
Network
|
wuzhicms
|
wuzhicms
|
Blacklist bypass issue exists in WUZHI CMS up to and including 4.1.0 in common.func.php, which when uploaded can cause remote code executiong.
|
CWE-863
Incorrect Authorization
|
CVE-2020-19551
|
2024-11-21 14:09 |
2021-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211248
|
6.1 |
MEDIUM
Network
|
wuzhicms
|
wuzhicms
|
Cross Site Scripting (XSS vulnerability exists in WUZHI CMS 4.1.0 via the mailbox username in index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19915
|
2024-11-21 14:09 |
2021-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211249
|
6.1 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19295
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211250
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
A stored cross-site scripting (XSS) vulnerability in the /article/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the article comm…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19294
|
2024-11-21 14:09 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|