Umbraco是丹麦Umbraco公司的一套C#编写的开源的内容管理系统(CMS)。 Umbraco CMS 8.9.1版本及之前版本存在跨站脚本漏洞,该漏洞允许经过身份验证的用户可以在使用TinyMCE富文本编辑器编辑内容时将任意JavaScript代码注入到iframes中,因为TinyMCE被配置为默认允许在Umbraco CMS中使用iframes。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Umbraco CMS | <= 8.9.1 or current (unfixed) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-28413 | 5.3 MEDIUM | MantisBT SQL注入漏洞 |
| CVE-2020-29231 | Egavilanmedia User Registration & Login System 跨站脚本漏洞 | |
| CVE-2020-35847 | Agentejo Cockpit SQL注入漏洞 | |
| CVE-2020-29230 | Egavilanmedia User Registration & Login System 跨站脚本漏洞 | |
| CVE-2020-28365 | Sentrifugo 跨站脚本漏洞 | |
| CVE-2020-29228 | Egavilanmedia User Registration & Login System SQL注入漏洞 | |
| CVE-2020-35849 | MantisBT 安全漏洞 | |
| CVE-2020-5810 | Umbraco 跨站脚本漏洞 | |
| CVE-2020-5811 | Umbraco 路径遍历漏洞 | |
| CVE-2020-29233 | WonderCMS 跨站脚本漏洞 | |
| CVE-2020-29469 | WonderCMS 跨站脚本漏洞 | |
| CVE-2020-35241 | Flatpress 跨站脚本漏洞 | |
| CVE-2020-35240 | Fluxbb 跨站脚本漏洞 | |
| CVE-2020-29477 | Invision Community 跨站脚本漏洞 | |
| CVE-2020-29594 | Rocket.Chat 授权问题漏洞 | |
| CVE-2020-35850 | Agentejo Cockpit 代码问题漏洞 | |
| CVE-2020-35846 | Agentejo Cockpit SQL注入漏洞 | |
| CVE-2020-35848 | Agentejo Cockpit SQL注入漏洞 | |
| CVE-2020-27534 | Docker Engine 路径遍历漏洞 | |
| CVE-2020-35737 | Newgen Egov Correspondence Management System 安全漏洞 |
Showing top 20 of 37 CVEs. View all on vendor page → →
No comments yet