Medium
CVSS: 5.9
Lack of output escaping leads to a XSS vector in the pagebreak plugin.
Medium
CVSS: 5.9
Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
High
CVSS: 7.5
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Critical
CVSS: 9.8
Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x…
High
CVSS: 7.5
Improper Access Controls allows access to protected views.
High
CVSS: 7.5
Lack of output escaping in the id attribute of menu lists.
Medium
CVSS: 6.1
Various module chromes didn't properly process inputs, leading to XSS vectors.