CVE-2012-1899
Nikola Posa Webfoliocms - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in webfolio/admin/users/edit in Webfolio CMS 1.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) First name, (2) Last name or (3) Email (required) fields.
References (4)
Scores
EPSS
0.0029
EPSS Percentile
51.6%
Classification
CWE
CWE-79
Status
published
Affected Products (14)
nikola_posa/webfoliocms
nikola_posa/webfoliocms
nikola_posa/webfoliocms
nikola_posa/webfoliocms
nikola_posa/webfoliocms
nikola_posa/webfoliocms
nikola_posa/webfoliocms
nikola_posa/webfoliocms
nikola_posa/webfoliocms
nikola_posa/webfoliocms
nikola_posa/webfoliocms
nikola_posa/webfoliocms
nikola_posa/webfoliocms
n/a/n/a
Timeline
Published
Sep 17, 2012
Tracked Since
Feb 18, 2026