CVE-2011-3978
LightNEasy 3.2.4 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy.php in LightNEasy 3.2.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) commentemail, (2) commentmessage, or (3) commentname parameter in a sendcomment action for the news page.
References (7)
Scores
EPSS
0.0035
EPSS Percentile
57.1%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
lightneasy/lightneasy
n/a/n/a
Timeline
Published
Oct 04, 2011
Tracked Since
Feb 18, 2026