Cross-site scripting (XSS) vulnerability in Upload/engine.php in Chevereto 1.91 allows remote attackers to inject arbitrary web script or HTML via the v parameter.
5.9AI Score
0.002EPSS
Directory traversal vulnerability in Upload/engine.php in Chevereto 1.9.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in the v parameter.
6.9AI Score
0.012EPSS
Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data parser.
6.1CVSS
6AI Score
0.001EPSS
5.4CVSS
5.5AI Score
0.001EPSS
Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage.
6.1CVSS
6AI Score
0.005EPSS