|
208941
|
4.8 |
MEDIUM
Network
|
pbootcms
|
pbootcms
|
Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18456
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208942
|
4.8 |
MEDIUM
Network
|
bycms_project
|
bycms
|
Cross Site Scripting (XSS) vulnerability exists in bycms v3.0.4 via the title parameter in the edit function in Document.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18455
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208943
|
6.8 |
MEDIUM
Network
|
bycms_project
|
bycms
|
Cross Site Request Forgery (CSRF) vulnerability in bycms v1.3 via admin.php/systems/index/module_id/70/group_id/1.html.
|
CWE-352
Origin Validation Error
|
CVE-2020-18454
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208944
|
4.8 |
MEDIUM
Network
|
damicms
|
damicms
|
Cross Site Scripting (XSS) vulnerability exists in DamiCMS v6.0.6 via the title parameter in the doadd function in LabelAction.class.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18451
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208945
|
5.4 |
MEDIUM
Network
|
ukcms
|
ukcms
|
Cross Site Scripting (XSS) vulnerability exists in UKCMS v1.1.10 via data in the index function in Single.php
|
CWE-79
Cross-site Scripting
|
CVE-2020-18449
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208946
|
4.8 |
MEDIUM
Network
|
yunucms
|
yunucms
|
Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18446
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208947
|
6.1 |
MEDIUM
Network
|
yunucms
|
yunucms
|
Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18445
|
2024-11-21 14:08 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208948
|
8.8 |
HIGH
Network
|
ignitedcms
|
ignitedcms
|
Cross Site Request Forgery (CSRF) in IgnitedCMS v1.0 allows remote attackers to obtain sensitive information and gain privilege via the component "/admin/profile/save_profile".
|
CWE-352
Origin Validation Error
|
CVE-2020-18694
|
2024-11-21 14:08 |
2021-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208949
|
5.4 |
MEDIUM
Network
|
mineweb
|
minewebcms
|
Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious code into the 'Title' field of the component '/admin/news'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18693
|
2024-11-21 14:08 |
2021-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208950
|
5.4 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
Cross Site Scripting (XSS) vulnerabiity in YzmCMS 5.2 via the site_code parameter in admin/index/init.html.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19118
|
2024-11-21 14:08 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|