Vulnerabilities (CVE)

Filtered by vendor Webreinvent Subscribe
Filtered by product Vaahcms
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-61183 1 Webreinvent 1 Vaahcms 2025-10-09 N/A 6.1 MEDIUM
Cross Site Scripting in vaahcms v.2.3.1 allows a remote attacker to execute arbitrary code via upload method in the storeAvatar() method of UserBase.php