|
209771
|
4.8 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
The Admin CP in vBulletin 5.6.3 allows XSS via the Paid Subscription Email Notification field in the Options.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25121
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209772
|
4.8 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
The Admin CP in vBulletin 5.6.3 allows XSS via the admincp/search.php?do=dosearch URI.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25120
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209773
|
4.8 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
The Admin CP in vBulletin 5.6.3 allows XSS via a Title of a Child Help Item in the Login/Logoff part of the User Manual.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25119
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209774
|
4.8 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
The Admin CP in vBulletin 5.6.3 allows XSS via a Style Options Settings Title to Styles Manager.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25118
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209775
|
4.8 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
The Admin CP in vBulletin 5.6.3 allows XSS via a Junior Member Title to User Title Manager.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25117
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209776
|
4.8 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25116
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209777
|
4.8 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25115
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209778
|
6.1 |
MEDIUM
Network
|
advanced_reports_project
|
advanced_reports
|
silverstripe-advancedreports (aka the Advanced Reports module for SilverStripe) 1.0 through 2.0 is vulnerable to Cross-Site Scripting (XSS) because it is possible to inject and store malicious JavaSc…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25102
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209779
|
9.8 |
CRITICAL
Network
|
eramba
|
eramba
|
eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2020-25105
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209780
|
5.4 |
MEDIUM
Network
|
eramba
|
eramba
|
eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For example, the filename has a complete XSS payload followed by the .png extension.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25104
|
2024-11-21 14:17 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|