CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
CVE-2007-3331 MEDIUM
Cross-site request forgery (CSRF) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to change the admin password via (1) a certain HTML form that…
CVSS 5.0 EPSS 1.18% Jun 21, 2007
CVE-2007-3330 MEDIUM
Cross-site scripting (XSS) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to inject arbitrary web script or HTML via a news post, which is sto…
CVSS 4.3 EPSS 1.06% Jun 21, 2007
CVE-2006-6866 HIGH
STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, ema…
CVSS 7.8 EPSS 3.11% Jan 4, 2007
Showing 1 to 3 CVEs · page 1