CVE-2014-2860
Paperthin Commonspot Content Server < 7.0.1 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to inject arbitrary web script or HTML via a crafted HTTP request to a (1) ColdFusion or (2) JavaScript component.
Scores
EPSS
0.0020
EPSS Percentile
41.8%
Details
CWE
CWE-79
Status
published
Products (5)
paperthin/commonspot_content_server
< 7.0.1
paperthin/commonspot_content_server
paperthin/commonspot_content_server
paperthin/commonspot_content_server
n/a/n/a
Published
Apr 15, 2014
Tracked Since
Feb 18, 2026