CrafterCMS Engine is vulnerable to reflected cross-site scripting (XSS) via the transformerName parameter in the /api/1/site/url/transform endpoint, allowing attackers to execute arbitrary JavaScript in the context of the user.
id: CVE-2023-4136
info:
name: CrafterCMS Engine - Cross-Site Scripting
author: ritikchaddha
s
...