Vulnerabilities > Craftedweb Project

DATE CVE VULNERABILITY TITLE RISK
2018-09-04 CVE-2018-16450 Cross-site Scripting vulnerability in Craftedweb Project Craftedweb 20130924
CraftedWeb through 2013-09-24 has reflected XSS via the p parameter.
network
low complexity
craftedweb-project CWE-79
6.1
2018-06-27 CVE-2018-12919 Cross-site Scripting vulnerability in Craftedweb Project Craftedweb 20130924
In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter.
network
low complexity
craftedweb-project CWE-79
6.1