Vulnerabilities > Chevereto > Chevereto > 3.5.4
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-06-30 | CVE-2021-31721 | Cross-site Scripting vulnerability in Chevereto Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage. | 6.1 |
2017-07-17 | CVE-2017-1000058 | Cross-site Scripting vulnerability in Chevereto Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data parser. | 6.1 |