Vulnerabilities > Sitemagic > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-10-23 CVE-2019-18219 Cross-site Scripting vulnerability in Sitemagic 4.4.1
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input.
network
low complexity
sitemagic CWE-79
6.1
2019-03-27 CVE-2019-10238 Cross-site Scripting vulnerability in Sitemagic 4.4
Sitemagic CMS v4.4 has XSS in SMFiles/FrmUpload.class.php via the filename parameter.
network
low complexity
sitemagic CWE-79
6.1