4.8

CVSS4.0

CVE-2025-27802 - Stored Cross-Site Scripting in Episerver Content Management System (CMS) Edit Preview

The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. RTE properties (text fields), which could be used in the "Edi…

πŸ“… Published: July 28, 2025, 8:47 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS4.0

CVE-2025-27801 - Stored Cross-Site Scripting in Episerver Content Management System (CMS) Media Selection Preview

The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. ContentReference properties, which could be used in the "Ed…

πŸ“… Published: July 28, 2025, 8:40 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-27800 - Stored Cross-Site Scripting in Episerver Content Management System (CMS) Admin Dashboard

The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. The Admin dashboard offered the functionality to add gadget…

πŸ“… Published: July 28, 2025, 8:33 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-8266 - yanyutao0402 ChanCMS collect.js getArticle deserialization

A vulnerability has been found in yanyutao0402 ChanCMS up to 3.1.2 and classified as critical. Affected by this vulnerability is the function getArticle of the file app/modules/cms/controller/collect.js. The manipulation of the argument targetUrl leads to deserialization. The attack can be launched…

πŸ“… Published: July 28, 2025, 8:32 a.m. πŸ”„ Last Modified: Aug. 27, 2025, 4:24 p.m.

5.1

CVSS4.0

CVE-2025-8265 - 299Ko CMS File Management view unrestricted upload

A vulnerability classified as critical has been found in 299Ko CMS 2.0.0. This affects an unknown part of the file /admin/filemanager/view of the component File Management. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed …

πŸ“… Published: July 28, 2025, 8:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-8263 - prettier: prettier parseNestedCSS ReDoS

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“… Published: July 28, 2025, 7:32 a.m. πŸ”„ Last Modified: Aug. 2, 2025, 9:15 a.m.

5.3

CVSS4.0

CVE-2025-8262 - yarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redos

A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of the file src/resolvers/exotics/hosted-git-resolver.js. The manipulation leads to inefficient regular expression complexity. It is possible to launch t…

πŸ“… Published: July 28, 2025, 7:02 a.m. πŸ”„ Last Modified: July 31, 2025, 7:16 p.m.

6.9

CVSS4.0

CVE-2025-8261 - Vaelsys VaelsysV4 User Creation vgrid_server.php improper authorization

A weakness has been identified in Vaelsys VaelsysV4 4.1.0. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the component User Creation Handler. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been ma…

πŸ“… Published: July 28, 2025, 6:32 a.m. πŸ”„ Last Modified: April 22, 2026, 1 p.m.

2.3

CVSS4.0

CVE-2025-8260 - Vaelsys VaelsysV4 Web interface vgrid_server.php weak hash

A security flaw has been discovered in Vaelsys VaelsysV4 up to 5.1.0/5.4.0. This affects an unknown part of the file /grid/vgrid_server.php of the component Web interface. Performing a manipulation of the argument xajaxargs results in use of weak hash. The attack is possible to be carried out remot…

πŸ“… Published: July 28, 2025, 6:02 a.m. πŸ”„ Last Modified: April 20, 2026, 4:30 p.m.

6.9

CVSS4.0

CVE-2025-8259 - Vaelsys VaelsysV4 Web interface vgrid_server.php execute_DataObjectProc os command injection

A vulnerability was identified in Vaelsys VaelsysV4 up to 5.1.0/5.4.0. Affected by this issue is the function execute_DataObjectProc of the file /grid/vgrid_server.php of the component Web interface. Such manipulation of the argument xajaxargs leads to os command injection. The attack can be execut…

πŸ“… Published: July 28, 2025, 5:32 a.m. πŸ”„ Last Modified: April 20, 2026, 4:30 p.m.
Total resulsts: 346671
Page 4238 of 34,668
Β« previous page Β» next page
Filters