Vulnerabilities > Kiwitcms

DATE CVE VULNERABILITY TITLE RISK
2022-11-21 CVE-2022-4105 Cross-site Scripting vulnerability in Kiwitcms Kiwi Tcms
A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page.
network
low complexity
kiwitcms CWE-79
5.4