Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Alyssa-O-Herrera

#20742of 53,633
12.2Total CVSS
Vulnerabilities · 2
Medium
2
PT-2018-17986
6.1
2018-02-20
Shimmie · Shimmie 2 · CVE-2018-7265
**Name of the Vulnerable Software and Affected Versions** Shimmie 2 version 2.6.0 **Description** The issue allows an attacker to upload a crafted SVG file, enabling stored XSS. **Recommendations** For Shimmie 2 version 2.6.0, update to a version that fixes this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2018-17943
6.1
2018-02-18
Pluck · Pluck · CVE-2018-7197
**Name of the Vulnerable Software and Affected Versions** Pluck versions prior to 4.7.5 **Description** A stored cross-site scripting issue allows remote unauthenticated users to inject arbitrary web script or HTML into admin/blog Reaction Comments via a crafted URL. **Recommendations** For versions prior to 4.7.5, update to version 4.7.5 or later to resolve the issue.