VYPR

News Lister

by Netartmedia

CVEs (2)

  • CVE-2020-37236MedMay 16, 2026
    risk 0.42cvss 6.4epss 0.00

    NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the title parameter in the news addition interface. Attackers can inject JavaScript payloads via the title field in the…

  • CVE-2020-29364MedNov 30, 2020
    risk 0.31cvss 4.8epss 0.01

    In NetArt News Lister 1.0.0, the news headlines vulnerable to stored xss attacks. Attackers can inject codes in news titles.