Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
5.4
CVE-2018-16624
- EPSS 0.7%
- Veröffentlicht 13.05.2019 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:53:04
panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.
4.8
CVE-2018-16623
- EPSS 0.68%
- Veröffentlicht 13.05.2019 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:53:04
Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown.
4.8
CVE-2018-16630
- EPSS 0.56%
- Veröffentlicht 28.12.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:05
Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file.
6.1
CVE-2018-16627
- EPSS 0.75%
- Veröffentlicht 20.12.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:05
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
5.4
CVE-2018-16628
- EPSS 0.57%
- Veröffentlicht 04.12.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:05
panel/login in Kirby v2.5.12 allows XSS via a blog name.