VendorsDot Net Foundationpiranha_cms11.1
Vulnerabilities

Dot Net Foundation Piranha CMS 11.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2024-55342
A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /manager/media. This PDF can contain malicious JavaScript code, which is executed when a victim user opens or interacts with the PDF in their web browser, leading to a XSS vulnerability.
Published 2024-12-20 · Analyzed
4.7EPSS 0.005
CVE-2024-55341
A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by creating a page via the /manager/pages and then adding a markdown content with the XSS payload.
Published 2024-12-20 · Analyzed
4.7EPSS 0.004