Vulnerabilities > Symphony CMS

DATE CVE VULNERABILITY TITLE RISK
2024-08-13 CVE-2024-41613 Cross-site Scripting vulnerability in Symphony-Cms Symphony CMS 2.7.10
A Cross Site Scripting (XSS) vulnerability in Symphony CMS 2.7.10 allows remote attackers to inject arbitrary web script or HTML by editing note.
network
low complexity
symphony-cms CWE-79
5.4
2024-08-13 CVE-2024-41614 Cross-site Scripting vulnerability in Symphony-Cms Symphony CMS
symphonycms <=2.7.10 is vulnerable to Cross Site Scripting (XSS) in the Comment component for articles.
network
low complexity
symphony-cms CWE-79
4.8