This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Chevereto First view 2017-07-17
Product Chevereto Last view 2021-06-30
Version * Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:chevereto:chevereto

Activity : Overall

Related : CVE

  Date Alert Description
6.1 2021-06-30 CVE-2021-31721

Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage.

5.4 2018-06-15 CVE-2018-12030

Chevereto Free before 1.0.13 has XSS.

6.1 2017-07-17 CVE-2017-1000058

Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data parser.

CWE : Common Weakness Enumeration

%idName
100% (3) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')