Vulnerabilities (CVE)

Filtered by vendor Wbce Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-30073 1 Wbce 1 Wbce Cms 2022-05-26 3.5 LOW 5.4 MEDIUM
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php.
CVE-2022-30072 1 Wbce 1 Wbce Cms 2022-05-25 3.5 LOW 5.4 MEDIUM
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters.
CVE-2022-28477 1 Wbce 1 Wbce Cms 2022-05-06 4.3 MEDIUM 6.1 MEDIUM
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2018-6313 1 Wbce 1 Wbce Cms 2018-02-08 3.5 LOW 4.8 MEDIUM
Cross-site scripting (XSS) in WBCE CMS 1.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the Modify Page screen, a different issue than CVE-2017-2118.
CVE-2017-1000213 1 Wbce 1 Wbce Cms 2017-11-29 3.5 LOW 4.8 MEDIUM
WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search
CVE-2017-2118 1 Wbce 1 Wbce Cms 2017-05-02 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.