Craft CMS 126.96.36.199 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
Craft CMS 188.8.131.52 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.
Craft CMS 184.108.40.206 is vulnerable to Cross Site Scripting (XSS) via Drafts.
Craft CMS 220.127.116.11 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.
Craft CMS 18.104.22.168 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.
Craft CMS before 3.7.29 allows XSS.
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).
An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.
Craft CMS before 3.6.13 has an XSS vulnerability.
Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new.
The Seomatic component before 3.2.46 for Craft CMS allows Server-Side Template Injection and information disclosure via malformed data to the metacontainers controller.
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
Craft CMS 3.1.30 has XSS.