Vulnerabilities (CVE)

Filtered by vendor Metalgenix Subscribe
Filtered by product Genixcms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-14476 1 Metalgenix 1 Genixcms 2020-03-17 4.3 MEDIUM 6.1 MEDIUM
GeniXCMS 1.1.5 has XSS via the dbuser or dbhost parameter during step 1 of installation.
CVE-2017-5515 1 Metalgenix 1 Genixcms 2017-01-23 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the user prompt function in GeniXCMS through 0.0.8 allows remote authenticated users to inject arbitrary web script or HTML via tag names.
CVE-2017-5516 1 Metalgenix 1 Genixcms 2017-01-23 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the user forms in GeniXCMS through 0.0.8 allow remote attackers to inject arbitrary web script or HTML via crafted parameters.