CVE-2011-4764
Parallels Plesk Small Business Panel - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by Wizard/Edit/Modules/Image and certain other files.
Scores
EPSS
0.0022
EPSS Percentile
45.0%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
parallels/parallels_plesk_small_business_panel
n/a/n/a
Timeline
Published
Dec 16, 2011
Tracked Since
Feb 18, 2026