Vulnerabilities > Nedi > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-07-07 CVE-2020-15037 Cross-site Scripting vulnerability in Nedi 1.9C
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
network
low complexity
nedi CWE-79
5.4
2020-07-07 CVE-2020-15036 Cross-site Scripting vulnerability in Nedi 1.9C
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack.
network
low complexity
nedi CWE-79
5.4
2020-06-29 CVE-2020-14413 Cross-site Scripting vulnerability in Nedi 1.9C
NeDi 1.9C is vulnerable to XSS because of an incorrect implementation of sanitize() in inc/libmisc.php.
network
low complexity
nedi CWE-79
6.1
2020-06-26 CVE-2020-15017 Cross-site Scripting vulnerability in Nedi 1.9C
NeDi 1.9C is vulnerable to reflected cross-site scripting.
network
low complexity
nedi CWE-79
6.1
2020-06-26 CVE-2020-15016 Cross-site Scripting vulnerability in Nedi 1.9C
NeDi 1.9C is vulnerable to reflected cross-site scripting.
network
low complexity
nedi CWE-79
6.1
2019-01-17 CVE-2018-20731 Cross-site Scripting vulnerability in Nedi
A stored cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML via User-Chat.php.
network
low complexity
nedi CWE-79
6.1
2019-01-17 CVE-2018-20729 Cross-site Scripting vulnerability in Nedi
A reflected cross site scripting (XSS) vulnerability in NeDi before 1.7Cp3 allows remote attackers to inject arbitrary web script or HTML via the reg parameter in mh.php.
network
low complexity
nedi CWE-79
6.1