News
This hub aggregates every CVE we track for News, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
10
CVEs tracked
1
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM6HIGH3CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-082026-07
Latest CVEs
The 10 most recently published vulnerabilities affecting News.
- CVE-2021-41256Intent URI permissions manipulation in nextcloud news-android5.8
- CVE-2019-12724An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter.6.1
- CVE-2017-15982Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.9.8
- CVE-2014-6290The News (tt_news) extension before 3.5.2 for TYPO3 allows remote attackers to have unspecified impact via vectors related to an "insecure unserialize" issue.7.5
- CVE-2013-4748SQL injection vulnerability in the News system (news) extension before 1.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.7.5
- CVE-2011-3851Cross-site scripting (XSS) vulnerability in the News theme before 0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.4.3
- CVE-2007-6540SQL injection vulnerability in neuron news 1.0 allows remote attackers to execute arbitrary SQL commands via the q parameter to the default URI in patch/.7.5
- CVE-2006-3384SQL injection vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) texte parameters.5.1
- CVE-2006-3386index.php in Vincent Leclercq News 5.2 allows remote attackers to obtain sensitive information, such as the installation path, via a mail[] parameter with invalid values.5.0
- CVE-2006-3385Cross-site scripting (XSS) vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) id and (2) disabled parameters.5.8
Product normalization is registry-driven with AI assist and human review. How it works