CVE-2022-38550
- EPSS 0.2%
- Veröffentlicht 19.09.2022 23:15:09
- Zuletzt bearbeitet 27.05.2025 18:15:29
A stored cross-site scripting (XSS) vulnerability in the /weibo/list component of Jeesns v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2020-19295
- EPSS 13.64%
- Veröffentlicht 09.09.2021 23:15:10
- Zuletzt bearbeitet 21.11.2024 05:09:07
A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.
CVE-2020-19294
- EPSS 0.19%
- Veröffentlicht 09.09.2021 23:15:10
- Zuletzt bearbeitet 21.11.2024 05:09:07
A stored cross-site scripting (XSS) vulnerability in the /article/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the article comments section.
CVE-2020-19286
- EPSS 0.19%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:05
A stored cross-site scripting (XSS) vulnerability in the /question/detail component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the source field of the editor.
CVE-2020-19293
- EPSS 0.19%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:06
A stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted article.
CVE-2020-19292
- EPSS 0.19%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:06
A stored cross-site scripting (XSS) vulnerability in the /question/ask component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted question.
CVE-2020-19291
- EPSS 0.15%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:06
A stored cross-site scripting (XSS) vulnerability in the /weibo/publishdata component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted Weibo.
CVE-2020-19290
- EPSS 0.19%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:06
A stored cross-site scripting (XSS) vulnerability in the /weibo/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Weibo comment section.
CVE-2020-19289
- EPSS 0.26%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:06
A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the new album tab.
CVE-2020-19288
- EPSS 0.19%
- Veröffentlicht 09.09.2021 23:15:09
- Zuletzt bearbeitet 21.11.2024 05:09:06
A stored cross-site scripting (XSS) vulnerability in the /localhost/u component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a private message.