Vulnerabilities > Websitebaker > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-01-10 CVE-2017-16514 Cross-site Scripting vulnerability in Websitebaker 2.10.0
Multiple persistent stored Cross-Site-Scripting (XSS) vulnerabilities in the files /wb/admin/admintools/tool.php (Droplet Description) and /install/index.php (Site Title) in WebsiteBaker 2.10.0 allow attackers to insert persistent JavaScript code that gets reflected back to users in multiple areas in the application.
network
low complexity
websitebaker CWE-79
6.1
2017-06-02 CVE-2017-9361 Cross-site Scripting vulnerability in Websitebaker 2.10.0
WebsiteBaker v2.10.0 has a stored XSS vulnerability in /account/details.php.
network
low complexity
websitebaker CWE-79
6.1