CVE-2013-1470
Geeklog - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in calendar/index.php in the Calendar plugin in Geeklog before 1.8.2sr1 and 2.0.0 before 2.0.0rc2 allows remote attackers to inject arbitrary web script or HTML via the calendar_type parameter to submit.php.
References (5)
Scores
EPSS
0.0040
EPSS Percentile
60.4%
Details
CWE
CWE-79
Status
published
Products (4)
geeklog/geeklog
geeklog/geeklog
geeklog/geeklog
n/a/n/a
Published
Feb 05, 2014
Tracked Since
Feb 18, 2026