ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-16450
CraftedWeb through 2013-09-24 has reflected XSS via the p parameter.

CraftedWeb through 2013-09-24 has reflected XSS via the p parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • craftedweb project craftedweb
CVE-2018-12919
In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter.

In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • craftedweb project craftedweb