Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-37131: YznCMS v1.1.0 has a CSRF vulnerability that can be used to change administrator passwords · Issue #2 · ken678/yzncms

A Cross-Site Request Forgery (CSRF) in the component /public/admin/profile/update.html of YznCMS v1.1.0 allows attackers to arbitrarily change the Administrator password via a crafted POST request.

CVE
#csrf#vulnerability#git
CVE-2023-36970: CMS Made Simple v2.2.17 – Stored Cross-Site Scripting (XSS) (Authenticated)

A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.

CVE-2023-37134: EyouCMS V1.6.3 "Basic Information" module has a storage cross-site vulnerability · Issue #47 · weng-xianhu/eyoucms

A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-37132: Stored XSS exists in version 1.6.3, which can lead to stealing sensitive information of logged-in users · Issue #45 · weng-xianhu/eyoucms

A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-37136: EyouCMS V1.6.3 "Basic Website Information" module has cross-site storage vulnerability · Issue #49 · weng-xianhu/eyoucms

A stored cross-site scripting (XSS) vulnerability in the Basic Website Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-37135: EyouCMS V1.6.3 "Image Upload" module has cross-site storage vulnerability · Issue #48 · weng-xianhu/eyoucms

A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-37133: The "Column management" module of eyoucms1.6.3 has a storage XSS vulnerability · Issue #46 · weng-xianhu/eyoucms

A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-37124: SEACMS V12.1 has storage XSS vulnerability · Issue #24 · seacms-com/seacms

A stored cross-site scripting (XSS) vulnerability in the Site Setup module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-37125: SEACMS V12.1 has storage XSS vulnerability · Issue #25 · seacms-com/seacms

A stored cross-site scripting (XSS) vulnerability in the Management Custom label module of SEACMS v12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-37122: BageCms3.1.0 has storage XSS vulnerability · Issue #6 · bagesoft/bagecms

A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Settings module.