|
212241
|
6.1 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. N…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12708
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212242
|
6.1 |
MEDIUM
Network
|
lepton-cms
|
lepton_cms
|
An XSS vulnerability exists in modules/wysiwyg/save.php of LeptonCMS 4.5.0. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT elements. A malicious a…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12707
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212243
|
5.4 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12706
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212244
|
6.1 |
MEDIUM
Network
|
lepton-cms
|
leptoncms
|
Multiple cross-site scripting (XSS) vulnerabilities exist in LeptonCMS before 4.6.0.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12705
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212245
|
6.1 |
MEDIUM
Network
|
ulicms
|
ulicms
|
UliCMS before 2020.2 has PageController stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12704
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212246
|
6.1 |
MEDIUM
Network
|
ulicms
|
ulicms
|
UliCMS before 2020.2 has XSS during PackageController uninstall.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12703
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212247
|
6.1 |
MEDIUM
Network
|
mitel
|
shoretel_conference_web mivoice_connect
|
A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 allows remote attackers to inject arbitrary JavaScri…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12679
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212248
|
6.5 |
MEDIUM
Network
|
serpico_project
|
serpico
|
An issue was discovered in Serpico before 1.3.3. The /admin/attacments_backup endpoint can be requested by non-admin authenticated users. This means that an attacker with a user account can retrieve …
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-12687
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212249
|
5.4 |
MEDIUM
Network
|
katyshop2_project
|
katyshop2
|
Katyshop2 before 2.12 has multiple stored XSS issues.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12683
|
2024-11-21 14:00 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212250
|
6.1 |
MEDIUM
Network
|
iframe_project
|
iframe
|
The iframe plugin before 4.5 for WordPress does not sanitize a URL.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12696
|
2024-11-21 14:00 |
2020-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|