361,800
Total CVEs
26,223
Critical
85,816
High
1,626
CISA KEV
802
This Week
14 results · Page 1/1
ExpressionEngine before 7.4.11 allows XSS.
expressionengine
A vulnerability, which was classified as critical, has been found in 个人开源 mldong 1.0. This issue affects the function ExpressionEngine of the file com/mldong/modules/wf/engine/model/DecisionModel.java. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251561 was assigned to this vulnerability.
garethhk
In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user.
expressionengine
Unsanitized user input in ExpressionEngine <= 5.4.0 control panel member creation leads to an SQL injection. The user needs member creation/admin control panel access to execute the attack.
expressionengine