CVE-2009-2595

Censura <2.1.0 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a ProductSearch action.

Exploits (1)

exploitdb WRITEUP
by mark99 · textwebappsphp
https://www.exploit-db.com/exploits/33144

Scores

EPSS 0.0084
EPSS Percentile 74.6%

Classification

CWE
CWE-79
Status published

Affected Products (3)

censura/censura
censura/censura
n/a/n/a

Timeline

Published Jul 24, 2009
Tracked Since Feb 18, 2026