Vulnerabilities (CVE)

Filtered by vendor Sitecore Subscribe
Filtered by product Experience Platform
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-13493 1 Sitecore 1 Experience Platform 2019-07-18 3.5 LOW 5.4 MEDIUM
In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged user can modify the uploaded file extension parameter to inject arbitrary JavaScript.
CVE-2016-8855 1 Sitecore 1 Experience Platform 2017-03-21 4.3 MEDIUM 6.1 MEDIUM
Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. 160519 (8.1 Update-3) allows remote attacks via the Name or Description parameter. This is fixed in 8.2 Update-2.