Vulnerabilities > Chevereto

DATE CVE VULNERABILITY TITLE RISK
2021-06-30 CVE-2021-31721 Cross-site Scripting vulnerability in Chevereto
Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage.
network
low complexity
chevereto CWE-79
6.1
2018-06-15 CVE-2018-12030 Cross-site Scripting vulnerability in Chevereto
Chevereto Free before 1.0.13 has XSS.
network
low complexity
chevereto CWE-79
5.4
2017-07-17 CVE-2017-1000058 Cross-site Scripting vulnerability in Chevereto
Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data parser.
network
low complexity
chevereto CWE-79
6.1