Vulnerabilities (CVE)

Filtered by vendor Youphptube Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-25875 1 Youphptube 1 Youphptube 2021-11-08 4.3 MEDIUM 6.1 MEDIUM
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the searchPhrase parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.
CVE-2021-25876 1 Youphptube 1 Youphptube 2021-11-08 4.3 MEDIUM 6.1 MEDIUM
AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.
CVE-2021-25878 1 Youphptube 1 Youphptube 2021-11-08 4.3 MEDIUM 6.1 MEDIUM
AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.
CVE-2019-14430 1 Youphptube 1 Youphptube 2019-08-26 5.0 MEDIUM 5.3 MEDIUM
plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.