Vulnerabilities > Craftcms > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-04-25 CVE-2023-30177 Cross-site Scripting vulnerability in Craftcms Craft CMS 3.7.59
CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS).
network
low complexity
craftcms CWE-79
6.1
2023-03-03 CVE-2023-23927 Unspecified vulnerability in Craftcms Craft CMS
Craft is a platform for creating digital experiences.
network
low complexity
craftcms
5.4
2022-09-21 CVE-2022-37246 Cross-site Scripting vulnerability in Craftcms Craft CMS 4.2.0.1
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
network
low complexity
craftcms CWE-79
5.4
2022-09-16 CVE-2022-37247 Cross-site Scripting vulnerability in Craftcms Craft CMS 4.2.0.1
Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.
network
low complexity
craftcms CWE-79
5.4
2022-09-16 CVE-2022-37251 Cross-site Scripting vulnerability in Craftcms Craft CMS 4.2.0.1
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.
network
low complexity
craftcms CWE-79
5.4
2022-09-16 CVE-2022-37248 Cross-site Scripting vulnerability in Craftcms Craft CMS 4.2.0.1
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.
network
low complexity
craftcms CWE-79
5.4
2022-09-16 CVE-2022-37250 Cross-site Scripting vulnerability in Craftcms Craft CMS 4.2.0.1
Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.
network
low complexity
craftcms CWE-79
5.4
2022-04-03 CVE-2022-28378 Cross-site Scripting vulnerability in Craftcms Craft CMS
Craft CMS before 3.7.29 allows XSS.
network
low complexity
craftcms CWE-79
6.1
2021-06-30 CVE-2021-27902 Cross-site Scripting vulnerability in Craftcms Craft CMS
An issue was discovered in Craft CMS before 3.6.0.
network
low complexity
craftcms CWE-79
6.1
2021-05-07 CVE-2021-32470 Cross-site Scripting vulnerability in Craftcms Craft CMS
Craft CMS before 3.6.13 has an XSS vulnerability.
network
low complexity
craftcms CWE-79
6.1