Vulnerabilities > Chevereto > Chevereto > 3.2.1

DATE CVE VULNERABILITY TITLE RISK
2021-06-30 CVE-2021-31721 Cross-site Scripting vulnerability in Chevereto
Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage.
network
chevereto CWE-79
4.3
2017-07-17 CVE-2017-1000058 Cross-site Scripting vulnerability in Chevereto
Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data parser.
network
chevereto CWE-79
4.3