CVE-2026-97294
- EPSS 0.13%
- Veröffentlicht 07.10.2026 09:10:56
- Zuletzt bearbeitet 07.10.2026 13:24:53
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.41.
CVE-2026-97293
- EPSS 0.25%
- Veröffentlicht 30.09.2026 12:28:22
- Zuletzt bearbeitet 30.09.2026 14:18:18
Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
CVE-2026-66601
- EPSS -
- Veröffentlicht 20.08.2026 12:16:33
- Zuletzt bearbeitet 20.08.2026 16:17:43
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
CVE-2026-66600
- EPSS -
- Veröffentlicht 20.08.2026 12:16:33
- Zuletzt bearbeitet 20.08.2026 17:19:26
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
CVE-2026-66591
- EPSS 0.16%
- Veröffentlicht 18.08.2026 22:15:08
- Zuletzt bearbeitet 21.08.2026 17:16:40
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS. This issue affects Media LIbrary Assistant: from n/a through 3.39.
CVE-2026-61963
- EPSS 0.18%
- Veröffentlicht 06.08.2026 14:27:20
- Zuletzt bearbeitet 12.08.2026 20:58:37
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
CVE-2026-56012
- EPSS 0.36%
- Veröffentlicht 18.06.2026 14:02:38
- Zuletzt bearbeitet 18.06.2026 14:02:38
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection. This issue affects Media LIbrary Assistant: from n/a through 3.35.
CVE-2026-54198
- EPSS 0.2%
- Veröffentlicht 16.06.2026 09:00:38
- Zuletzt bearbeitet 16.06.2026 14:52:36
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.
CVE-2026-34897
- EPSS 0.18%
- Veröffentlicht 06.04.2026 14:50:48
- Zuletzt bearbeitet 24.04.2026 18:08:35
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.34.
CVE-2026-34885
- EPSS 1.67%
- Veröffentlicht 06.04.2026 14:47:31
- Zuletzt bearbeitet 24.04.2026 18:08:35
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQL Injection.This issue affects Media LIbrary Assistant: from n/a through 3.34.