Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Newsscriptphp Subscribe
Filtered by product News Script Php Pro
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25473 1 Newsscriptphp 1 News Script Php Pro 2020-11-30 6.4 MEDIUM 6.5 MEDIUM
SimplePHPscripts News Script PHP Pro 2.3 does not properly set the HttpOnly Flag from Session Cookies.
CVE-2020-25472 1 Newsscriptphp 1 News Script Php Pro 2020-11-27 4.3 MEDIUM 6.5 MEDIUM
SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users.
CVE-2020-25475 1 Newsscriptphp 1 News Script Php Pro 2020-11-27 7.5 HIGH 9.8 CRITICAL
SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action.
CVE-2020-25474 1 Newsscriptphp 1 News Script Php Pro 2020-11-27 4.3 MEDIUM 6.1 MEDIUM
SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Scripting (XSS) vulnerability via the editor_name parameter.