Vulnerabilities > Nukeviet > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-11-13 CVE-2022-3975 Unspecified vulnerability in Nukeviet
A vulnerability, which was classified as problematic, has been found in NukeViet CMS.
network
low complexity
nukeviet
6.1
2022-06-21 CVE-2022-30874 Cross-site Scripting vulnerability in Nukeviet
There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.
network
low complexity
nukeviet CWE-79
5.4
2021-07-30 CVE-2020-22765 Cross-site Scripting vulnerability in Nukeviet 4.4.0
Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.
network
low complexity
nukeviet CWE-79
6.1
2020-06-23 CVE-2020-13157 Cross-Site Request Forgery (CSRF) vulnerability in Nukeviet 4.4
modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI.
network
low complexity
nukeviet CWE-352
6.5
2020-06-23 CVE-2020-13156 Cross-Site Request Forgery (CSRF) vulnerability in Nukeviet 4.4
modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.
network
low complexity
nukeviet CWE-352
6.5