VYPR

by Craftcms

CVEs (5)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-8384Med0.406.10.00May 1, 2017Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
CVE-2017-9516Med0.385.40.01Jun 8, 2017Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
CVE-2017-8383Med0.345.30.00May 1, 2017Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
CVE-2017-8052Med0.336.10.00Apr 22, 2017Craft CMS before 2.6.2974 allows XSS attacks.
CVE-2017-8385Med0.275.30.00May 1, 2017Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.