Vulnerabilities (CVE)

Filtered by vendor Fidra Software
Filtered by product Lighthouse Cms
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-4780 1 Fidra Software 1 Lighthouse Cms 2025-04-03 4.3 MEDIUM 3.7 LOW
Cross-site scripting (XSS) vulnerability in Fidra Lighthouse CMS 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in a query_string to the home page. NOTE: The vendor disputes this issue, saying "Lighthouse does not in any way make use of the PHP technology. [It] is an application server ... A technology like this cannot be susceptible to client-side cross-site-scripting-attacks on its own, but only applications created based on such a te ...

Show More