|
208091
|
4.8 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25116
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208092
|
4.8 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25115
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208093
|
6.1 |
MEDIUM
Network
|
advanced_reports_project
|
advanced_reports
|
silverstripe-advancedreports (aka the Advanced Reports module for SilverStripe) 1.0 through 2.0 is vulnerable to Cross-Site Scripting (XSS) because it is possible to inject and store malicious JavaSc…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25102
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208094
|
9.8 |
CRITICAL
Network
|
eramba
|
eramba
|
eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2020-25105
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208095
|
5.4 |
MEDIUM
Network
|
eramba
|
eramba
|
eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For example, the filename has a complete XSS payload followed by the .png extension.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25104
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208096
|
7.5 |
HIGH
Network
|
setelsa-security
|
conacwin
|
Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unauthenticated attacker to read internal files on the server via an http:IP:PORT/.…
|
CWE-22
Path Traversal
|
CVE-2020-25068
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208097
|
6.1 |
MEDIUM
Network
|
ecommerce-codeigniter-bootstrap_project
|
ecommerce-codeigniter-bootstrap
|
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25093
|
2024-11-21 14:17 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208098
|
6.1 |
MEDIUM
Network
|
ecommerce-codeigniter-bootstrap_project
|
ecommerce-codeigniter-bootstrap
|
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/clothesshop, application/views/templates/greenlabel, and application/views/templa…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25092
|
2024-11-21 14:17 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208099
|
6.1 |
MEDIUM
Network
|
ecommerce-codeigniter-bootstrap_project
|
ecommerce-codeigniter-bootstrap
|
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25091
|
2024-11-21 14:17 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208100
|
6.1 |
MEDIUM
Network
|
ecommerce-codeigniter-bootstrap_project
|
ecommerce-codeigniter-bootstrap
|
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25090
|
2024-11-21 14:17 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|