Search Results (43 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-19609 1 Showdoc 1 Showdoc 2024-11-21 N/A
ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content, or discovering a username in the JSON data at a diff URL.
CVE-2018-19433 1 Showdoc 1 Showdoc 2024-11-21 N/A
ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.
CVE-2018-16342 1 Showdoc 1 Showdoc 2024-11-21 N/A
ShowDoc v1.8.0 has XSS via a new page.