VendorsWayang-CMS Projectwayang-cmsall versions
Vulnerabilities

Wayang-CMS Project Wayang-CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2020-29147
A SQL injection vulnerability in wy_controlls/wy_side_visitor.php of Wayang-CMS v1.0 allows attackers to obtain sensitive database information.
Published 2021-07-14 · Modified
7.5EPSS 0.011
CVE-2020-29146
A cross site scripting (XSS) vulnerability in index.php of Wayang-CMS v1.0 allows attackers to execute arbitrary web scripts or HTML via a constructed payload created by adding the X-Forwarded-For field to the header.
Published 2021-07-14 · Modified
6.1EPSS 0.007