Sitecore / Cms
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2019-11198 | Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1)… | MEDIUM | 6.1 | Aug 5, 2019 |
| CVE-2019-9875 KEV | Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to execute arbitrary code by sending a seria… | HIGH | 8.8 | May 31, 2019 |
| CVE-2019-9874 KEV | Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unau… | CRITICAL | 9.8 | May 31, 2019 |
| CVE-2017-11440 | In Sitecore 8.2, there is absolute path traversal via the shell/Applications/Layouts/IDE.aspx fi parameter and the admin/LinqScratchPad.aspx Reference paramete… | MEDIUM | 4.9 | Jul 19, 2017 |
| CVE-2017-11439 | In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter. | MEDIUM | 5.4 | Jul 19, 2017 |
| CVE-2014-100004 | Cross-site scripting (XSS) vulnerability in Sitecore CMS before 7.0 Update-4 (rev. 140120) allows remote attackers to inject arbitrary web script or HTML via t… | MEDIUM | 4.3 | Jan 13, 2015 |
| CVE-2009-2163 | Cross-site scripting (XSS) vulnerability in login/default.aspx in Sitecore CMS before 6.0.2 Update-1 090507 allows remote attackers to inject arbitrary web scr… | MEDIUM | 4.3 | Jun 22, 2009 |
| CVE-2009-1055 | Unspecified vulnerability in the web service in Sitecore CMS 5.3.1 rev. 071114 allows remote authenticated users to gain access to security databases, and obta… | MEDIUM | 4.0 | Mar 24, 2009 |
Showing 1 to 8 of 8 CVEs