jahia
Web & CMS Pluginscommercial
Top products
Latest CVEs
The 3 most recently published vulnerabilities affecting jahia.
- CVE-2013-4624Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to inject arbitrary web script or HTML via (1) the site parameter to engines/manager....4.3
- CVE-2013-4617Jahia xCM before 6.6.2 does not include the HTTPOnly flag in a Set-Cookie header for the JSESSIONID cookie, which makes it easier for remote attackers to obtain potentially sensitive information vi...5.0
- CVE-2013-3920Cross-site scripting (XSS) vulnerability in Jahia xCM before 6.6.2 allows remote authenticated users to inject arbitrary web script or HTML via the "about me" field.3.5