Vulnerabilities > Verbb

DATE CVE VULNERABILITY TITLE RISK
2020-06-05 CVE-2020-13870 Cross-site Scripting vulnerability in Verbb Comments
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS.
network
verbb CWE-79
3.5
2020-06-05 CVE-2020-13869 Cross-site Scripting vulnerability in Verbb Comments
An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS.
network
verbb CWE-79
3.5
2020-06-05 CVE-2020-13868 Cross-Site Request Forgery (CSRF) vulnerability in Verbb Comments
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS.
network
verbb CWE-352
4.3
2020-05-25 CVE-2020-13486 Open Redirect vulnerability in Verbb Knock
The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection.
network
verbb CWE-601
5.8
2020-05-25 CVE-2020-13485 Incorrect Comparison vulnerability in Verbb Knock
The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.
network
low complexity
verbb CWE-697
6.4
2020-05-25 CVE-2020-13459 Cross-site Scripting vulnerability in Verbb Image Resizer
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS.
network
verbb CWE-79
3.5
2020-05-25 CVE-2020-13458 Cross-Site Request Forgery (CSRF) vulnerability in Verbb Image Resizer
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS.
network
verbb CWE-352
6.8