Vulnerabilities > Craftcms > Craft CMS > 3.1.2.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-07-26 | CVE-2019-14280 | Information Exposure vulnerability in Craftcms Craft CMS In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public. | 5.3 |
2019-06-18 | CVE-2019-12823 | Cross-site Scripting vulnerability in Craftcms Craft CMS Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS. | 6.1 |