CrafterCMS CrafterCMS 4.0.0

CPE Details

CrafterCMS CrafterCMS 4.0.0
4.0.0
2023-02-27 17:46 +00:00
2023-02-28 17:18 +00:00

Alerte pour un CPE

Stay informed of any changes for a specific CPE.
Alert management

CPE Name: cpe:2.3:a:craftercms:craftercms:4.0.0:-:*:*:*:*:*:*

Informations

Vendor

craftercms

Product

craftercms

Version

4.0.0

Update

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-4136 2023-08-03 13:33 +00:00 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.
7.4
HIGH
CVE-2023-33194 2023-05-26 20:30 +00:00 Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was patched in version 4.4.6.
4.8
MEDIUM
Click on the button to the left (OFF), to authorize the inscription of cookie improving the functionalities of the site. Click on the button to the left (Accept all), to unauthorize the inscription of cookie improving the functionalities of the site.