Search
Search Results (6 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-36468 | 1 Cutenews | 1 Cutenews | 2026-09-26 | 6.1 Medium |
| Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name containing any URL-encoded common XSS payload (such as "><script>alert(1)</script>). | ||||
| CVE-2026-36469 | 1 Cutenews | 1 Cutenews | 2026-09-26 | 9.1 Critical |
| CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's "Upload by URL" functionality). | ||||
| CVE-2026-36470 | 1 Cutenews | 1 Cutenews | 2026-09-26 | 5.8 Medium |
| CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into the response HTML unmodified/unescaped during POST messages to index.php. | ||||
| CVE-2026-36471 | 1 Cutenews | 1 Cutenews | 2026-09-26 | 5.8 Medium |
| Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables (including __referer) via a crafted base64-encoded serialized PHP payload submitted as a POST parameter. | ||||
| CVE-2026-36472 | 1 Cutenews | 1 Cutenews | 2026-09-26 | 5.2 Medium |
| CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in the context of an authenticated user's session via a javascript: URI rendered as an unsanitized clickable link on the msg_info page. | ||||
| CVE-2026-36467 | 1 Cutenews | 1 Cutenews | 2026-09-21 | 7.2 High |
| Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell. | ||||
Page 1 of 1.