CVE-2010-5303
TimThumb <1.15 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the displayError function in timthumb.php in TimThumb before 1.15 (r85), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to $errorString.
Scores
EPSS
0.0022
EPSS Percentile
45.1%
Details
CWE
CWE-79
Status
published
Products (2)
binarymoon/timthumb
< 1.09
n/a/n/a
Published
Aug 21, 2014
Tracked Since
Feb 18, 2026