1 results (0.003 seconds)

CVSS: 5.4EPSS: 0%CPEs: 2EXPL: 3

The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any user opens a particular blog hosted on an attackers' site, XSS may occur. El plugin Simple Blog de Wondercms versión 3.4.1, es vulnerable a una vulnerabilidad de tipo cross-site scripting (XSS) almacenado. Cuando cualquier usuario abre un blog particular alojado en el sitio de un atacante, puede producirse un ataque de tipo XSS • https://hackerone.com/reports/485748 https://hackerone.com/reports/647130 https://hackerone.com/reports/961046 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •