CVE-2025-22388
- EPSS 0.51%
- Veröffentlicht 04.01.2025 02:15:07
- Zuletzt bearbeitet 20.05.2025 20:11:04
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.22.0. A high-severity Stored Cross-Site Scripting (XSS) vulnerability exists in the CMS, allowing malicious actors to inject and execute arbitrary JavaScript code, potentially comprom...
- EPSS 0.42%
- Veröffentlicht 04.01.2025 02:15:07
- Zuletzt bearbeitet 20.05.2025 20:10:52
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS, where the application does not properly validate uploaded files. This allows the upload of potentially malicious file types, i...
CVE-2025-22390
- EPSS 0.24%
- Veröffentlicht 04.01.2025 02:15:07
- Zuletzt bearbeitet 20.05.2025 20:10:40
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficient enforcement of password complexity requirements. The application permits users to set passwords with a mini...
CVE-2023-31754
- EPSS 0.15%
- Veröffentlicht 14.11.2023 04:15:07
- Zuletzt bearbeitet 21.11.2024 08:02:14
Optimizely CMS UI before v12.16.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Admin panel.