CVE-2012-5164
Fork CMS <3.2.7 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML via the term parameter to (1) autocomplete.php, (2) search/ajax/autosuggest.php, (3) livesuggest.php, or (4) save.php in frontend/modules/search/ajax.
References (5)
Scores
EPSS
0.0045
EPSS Percentile
63.2%
Classification
CWE
CWE-79
Status
published
Affected Products (43)
fork-cms/fork_cms
< 3.2.6
fork-cms/fork_cms
fork-cms/fork_cms
fork-cms/fork_cms
fork-cms/fork_cms
fork-cms/fork_cms
fork-cms/fork_cms
fork-cms/fork_cms
fork-cms/fork_cms
fork-cms/fork_cms
fork-cms/fork_cms
fork-cms/fork_cms
fork-cms/fork_cms
fork-cms/fork_cms
fork-cms/fork_cms
... and 28 more
Timeline
Published
Sep 26, 2012
Tracked Since
Feb 18, 2026