CVE-2012-2936
Pligg CMS <1.2.2 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) page parameter to (a) admin/admin_comments.php or (b) admin/admin_links.php; or list parameter in a (3) move or (4) minimize action to (c) admin/admin_index.php.
References (8)
Scores
EPSS
0.0054
EPSS Percentile
67.5%
Classification
CWE
CWE-79
Status
published
Affected Products (24)
pligg/pligg_cms
pligg/pligg_cms
pligg/pligg_cms
pligg/pligg_cms
pligg/pligg_cms
pligg/pligg_cms
pligg/pligg_cms
pligg/pligg_cms
pligg/pligg_cms
pligg/pligg_cms
pligg/pligg_cms
pligg/pligg_cms
pligg/pligg_cms
pligg/pligg_cms
pligg/pligg_cms
... and 9 more
Timeline
Published
May 27, 2012
Tracked Since
Feb 18, 2026