Vulnerabilities (CVE)

Filtered by vendor Nukeviet Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-30874 1 Nukeviet 1 Nukeviet 2022-06-29 3.5 LOW 5.4 MEDIUM
There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.
CVE-2020-22765 1 Nukeviet 1 Nukeviet 2021-08-03 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.
CVE-2020-13156 1 Nukeviet 1 Nukeviet 2020-06-29 4.3 MEDIUM 6.5 MEDIUM
modules\users\admin\add_user.php in NukeViet 4.4 allows CSRF to add a user account via the admin/index.php?nv=users&op=user_add URI.
CVE-2020-13157 1 Nukeviet 1 Nukeviet 2020-06-29 4.3 MEDIUM 6.5 MEDIUM
modules\users\admin\edit.php in NukeViet 4.4 allows CSRF to change a user's password via an admin/index.php?nv=users&op=edit&userid= URI. The old password is not needed.