CVE-2012-4901

Template CMS <2.1.1 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Template CMS 2.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the themes_editor parameter in an add_template action to admin/index.php.

Exploits (1)

exploitdb WORKING POC
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/21742

Scores

EPSS 0.0485
EPSS Percentile 89.4%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

template_cms_project/template_cms < 2.1.1

Timeline

Published May 20, 2015
Tracked Since Feb 18, 2026