{"error":0,"message":null,"data":{"name":"White Label CMS","plugin":"white-label-cms","link":"https:\/\/wordpress.org\/plugins\/white-label-cms\/","latest":"1783570560","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"80ca31b6c16d35d2f9fc265c1aff4b9e791b65abcceb0efa0b7dae1248f42581","name":"White Label CMS [white-label-cms] < 2.2.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0422","name":"CVE-2022-0422","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0422","description":"[en] The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue","date":"2022-03-07"},{"id":"075b2487c8fbaa5c581a1d83a5b55dc8bb56d5c9","name":"White Label MS <= 2.2.8 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/white-label-cms\/white-label-ms-228-reflected-cross-site-scripting","description":"The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue","date":"2022-02-07"},{"id":"429be4eb-8a6b-4531-9465-9ef0d35c12cc","name":"White Label MS &lt; 2.2.9 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/429be4eb-8a6b-4531-9465-9ef0d35c12cc","description":"The plugin does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"674cc2165a39633853319e28be97d65bc23e018b1ee08364237be5fd1aec291f","name":"White Label CMS [white-label-cms] < 1.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2012-5387","name":"CVE-2012-5387","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2012-5387","description":"[en] Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify the developer name via the wlcms_o_developer_name parameter in a save action to wp-admin\/admin.php, as demonstrated by a developer name containing XSS sequences.","date":"2012-10-24"},{"id":"fadfc02284b5d14945a8dbfa91b39299927cb890","name":"WordPress White Label CMS Plugin <= 1.5.0 - CSRF","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/white-label-cms\/vulnerability\/wordpress-white-label-cms-plugin-1-4-0-csrf","description":"Because of this vulnerability in wlcms-plugin.php, the attackers can hijack the authentication of administrators for requests that modify the developer name via the wlcms_o_developer_name parameter in a save action to wp-admin\/admin.php.\nUpdate the plugin.","date":"2012-10-15"},{"id":"b558dbb216dfe0e0a0da6e3a162efa026054a86d","name":"White Label CMS < 1.5.1 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/white-label-cms\/white-label-cms-151-reflected-cross-site-scripting","description":"Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify the developer name via the wlcms_o_developer_name parameter in a save action to wp-admin\/admin.php, as demonstrated by a developer name containing XSS sequences.","date":"2012-10-21"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"b9beb028cd8fe72d6124fef07efdaf64ae8fb546543fdd970a29516c1d1bad0c","name":"White Label CMS [white-label-cms] < 1.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2012-5388","name":"CVE-2012-5388","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2012-5388","description":"[en] Cross-site scripting (XSS) vulnerability in wlcms-plugin.php in the White Label CMS plugin 1.5 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the wlcms_o_developer_name parameter in a save action to wp-admin\/admin.php, a related issue to CVE-2012-5387.","date":"2012-10-24"},{"id":"50b7d897a049d010950b542bebe8b1df7c4b053f","name":"WordPress White Label CMS Plugin <= 1.5 - XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/white-label-cms\/vulnerability\/wordpress-white-label-cms-plugin-1-5-xss","description":"Because of this vulnerability in wlcms-plugin.php, the authenticated administrators can inject arbitrary web script or HTML via the \"wlcms_o_developer_name\" parameter.\nUpdate the plugin.","date":"2012-10-15"},{"id":"9709d3aaf044e328ffe481d787e394e216df4de6","name":"White Label CMS < 1.5.1 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/white-label-cms\/white-label-cms-151-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in wlcms-plugin.php in the White Label CMS plugin 1.5 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the wlcms_o_developer_name parameter in a save action to wp-admin\/admin.php, a related issue to CVE-2012-5387.","date":"2012-10-21"},{"id":"9dc1eb2e-687e-4ff2-a76d-508bf078e677","name":"White Label CMS - Cross-Site Request Forgery","link":"https:\/\/wpscan.com\/vulnerability\/9dc1eb2e-687e-4ff2-a76d-508bf078e677","description":"The White Label CMS WordPress plugin was affected by a Cross-Site Request Forgery  security vulnerability.","date":null}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"e692a4e3e178b141c0f0df1dba2ccfa486e7bd4a22a0e1131c47d296656fc743","name":"White Label CMS [white-label-cms] < 1.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"41ec0b04dea68686cdb82b0de05f48c8383f9d07","name":"WordPress White Label CMS Plugin <= 1.5.2 - Stored Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/white-label-cms\/vulnerability\/wordpress-white-label-cms-plugin-1-5-2-stored-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2015-05-15"}],"impact":[]},{"uuid":"7014170d90fec5bee9427f2c90f322f8596e1c2317160ac6ed2210586dc9c6b6","name":"White Label CMS [white-label-cms] < 2.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-4302","name":"CVE-2022-4302","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-4302","description":"[en] The White Label CMS WordPress plugin before 2.5 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.","date":"2023-01-02"},{"id":"ef86ad201d89bf8ddce4168dc2615866aa5b6e69","name":"White Label CMS <= 2.4 - Authenticated (Administrator+) PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/white-label-cms\/white-label-cms-24-authenticated-administrator-php-object-injection","description":"The White Label CMS plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.4 via deserialization of untrusted input in the legacy_import function. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2022-12-08"},{"id":"6dab8777b3e1d0e7c9610e77318d81361b554075","name":"WordPress  White Label CMS Plugin  < 2.5 is vulnerable to PHP Object Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/white-label-cms\/vulnerability\/wordpress-white-label-cms-plugin-2-5-admin-php-object-injection-vulnerability","description":"Update the WordPress White Label CMS plugin to the latest available version (at least 2.5).\nthinhnguyen1337 discovered and reported this PHP Object Injection vulnerability in WordPress White Label CMS Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, denial of service, and more if a proper POP chain is present. This vulnerability has been fixed in version 2.5.","date":"2023-12-08"},{"id":"b7707a15-0987-4051-a8ac-7be2424bcb01","name":"White Label CMS &lt; 2.5 - Admin+ PHP Object Injection","link":"https:\/\/wpscan.com\/vulnerability\/b7707a15-0987-4051-a8ac-7be2424bcb01","description":"The plugin unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"0e5a875e5b48653f808f69f3a6914c8d515b3b3c129ec0ea1f5333f53a7321f3","name":"White Label CMS [white-label-cms] < 1.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ff0c22680f7144d6e3b09f5c586430cde28c0acc","name":"White Label CMS <= 1.5.2 - Cross-Site Request Forgery leading to Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/white-label-cms\/white-label-cms-152-cross-site-request-forgery-leading-to-stored-cross-site-scripting","description":"The White Label CMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the 'wlcmsImport' function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page via forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2015-04-29"}],"impact":[]},{"uuid":"198007e6791c1a29cce6befa7ef6f67743f4d87b16f85db7527f6d3ae892e5a7","name":"White Label CMS [white-label-cms] < 1.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"59bb5cf2-67a0-494c-a202-4b1a9db28f3b","name":"White Label CMS &lt;= 1.5.2 - Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/59bb5cf2-67a0-494c-a202-4b1a9db28f3b","description":"Due to a lack of CSRF protection, and lack of sanitation of user input, it is possible to trigger a Persistent XSS attack via a CSRF attack. This attack targets in particular the Import functionality, which is located in the &#039;wlcmsImport&#039; function, within the file &#039;\/white-label-cms\/wlcms-plugin.php&#039;. The path to execution is in the addition of the hook to the &#039;admin_menu&#039; action, to the &#039;wlcms_add_admin&#039; function. The &#039;wlcms_add_admin&#039; function allows triggering of the &#039;wlcmsImport&#039; function simply by providing an action parameter, with the value of &lsquo;import&rsquo;.\r\n\r\nDue to the lack of CSRF, it is possible &ndash; if an administrative user can be tempted to visit a malicious site &ndash; to inject HTML which will be displayed to all users, depending on the template in use, in the form of a custom IMG element. Providing an invalid URL to this element, and utilizing the &#039;onerror&#039; event, custom JS can be triggered, which can result in Privilege Escalation. The default WordPress template will trigger the XSS on all pages of the site, as will the default WordPress Administrative theme. This is made possible thanks to the ability to import wlcms options via the import functionality, overwriting current options.","date":null}],"impact":[]},{"uuid":"b28cd2ddd288434e12b9bd2fcab104b8830c8b26467f3e30509e18201f1fc86d","name":"White Label CMS [white-label-cms] < 2.7.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4280","name":"CVE-2024-4280","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4280","description":"[en] The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_plugin function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to reset plugin settings.","date":"2024-05-10"},{"id":"47f388a10d0257b1b5f233194b79e2564d20559f","name":"White Label CMS <= 2.7.3 - Missing Authorization to Plugin Settings Reset","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/white-label-cms\/white-label-cms-273-missing-authorization-to-plugin-settings-reset","description":"The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_plugin function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to reset plugin settings.","date":"2024-05-09"},{"id":"e86df5d9157ae34eb53b894df9f9ad7f8e5394b6","name":"WordPress White Label CMS Plugin <= 2.7.3 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/white-label-cms\/vulnerability\/wordpress-white-label-cms-plugin-2-7-3-missing-authorization-to-plugin-settings-reset-vulnerability","description":"<p>WordPress White Label CMS Plugin <= 2.7.3 is vulnerable to Broken Access Control<\/p><p>Software: White Label CMS<\/p><p>Link: https:\/\/wordpress.org\/plugins\/white-label-cms\/#developers<\/p><p>Affected Version <= 2.7.3<\/p><p>Fixed in version 2.7.4 <\/p>","date":"2024-05-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"46a8b6d0a7793983fcf8468091f4a8b8af728f75b284673bc067abf4b324fcbd","name":"White Label CMS [white-label-cms] < 2.7.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-43303","name":"CVE-2024-43303","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-43303","description":"[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in videousermanuals.Com White Label CMS allows Reflected XSS.This issue affects White Label CMS: from n\/a through 2.7.4.","date":"2024-08-18"},{"id":"69c49c3988a9f3b340a29e2c6dae42b5148b7dc5","name":"WordPress White Label CMS Plugin <= 2.7.4 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/white-label-cms\/vulnerability\/wordpress-white-label-cms-plugin-2-7-4-reflected-cross-site-scripting-xss-vulnerability","description":"<p>WordPress White Label CMS Plugin <= 2.7.4 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: White Label CMS<\/p><p>Link: https:\/\/wordpress.org\/plugins\/white-label-cms\/#developers<\/p><p>Affected Version <= 2.7.4<\/p><p>Fixed in version 2.7.5 <\/p>","date":"2024-08-16"},{"id":"ab81330026eadbd574760016f59f6b4c8e02c101","name":"White Label CMS <= 2.7.4 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/white-label-cms\/white-label-cms-274-reflected-cross-site-scripting","description":"The White Label CMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-08-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"2.8","impact":"3.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"3.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7413adbe65e479b8fee0cf24fb3579063ec6f9e2fb7902ba8b20a783e04cd666","name":"White Label CMS [white-label-cms] < 2.7.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-11898","name":"CVE-2026-11898","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-11898","description":"[en] The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2026-07-11"},{"id":"99d39c2661844003882f02773fd4e2090fc7b8ab","name":"White Label CMS <= 2.7.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/white-label-cms\/white-label-cms-2712-authenticated-administrator-stored-cross-site-scripting-via-import-settings","description":"The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2026-07-10"},{"id":"EUVD-2026-43150","name":"EUVD-2026-43150","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-43150","description":"The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2026-07-11"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:H\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"h","pr":"h","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"4.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:H\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"4.4","severity":"medium","av":"network","ac":"high","pr":"high","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"epss":"0.003"}}]},"updated":"1783750423"}