Jeesns 1.4.2 is vulnerable to reflected cross-site scripting in the /weibo/topic component and allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the system error message's text field.
id: CVE-2020-19295
info:
name: Jeesns 1.4.2 - Cross-Site Scripting
author: pikpikcu
severity:
...