News
This hub aggregates every CVE we track for News, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
10
CVEs tracked
1
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM6HIGH3CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 10 most recently published vulnerabilities affecting News.
- CVE-2021-41256Intent URI permissions manipulation in nextcloud news-android5.8
- CVE-2019-12724An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter.6.1
- CVE-2017-15982Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.9.8
- CVE-2014-6290The News (tt_news) extension before 3.5.2 for TYPO3 allows remote attackers to have unspecified impact via vectors related to an "insecure unserialize" issue.7.5
- CVE-2013-4748SQL injection vulnerability in the News system (news) extension before 1.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.7.5
- CVE-2011-3851Cross-site scripting (XSS) vulnerability in the News theme before 0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.4.3
- CVE-2007-6540SQL injection vulnerability in neuron news 1.0 allows remote attackers to execute arbitrary SQL commands via the q parameter to the default URI in patch/.7.5
- CVE-2006-3384SQL injection vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) texte parameters.5.1
- CVE-2006-3385Cross-site scripting (XSS) vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) id and (2) disabled parameters.5.8
- CVE-2006-3386index.php in Vincent Leclercq News 5.2 allows remote attackers to obtain sensitive information, such as the installation path, via a mail[] parameter with invalid values.5.0
Product normalization is registry-driven with AI assist and human review. How it works