Description
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
Remediation
References
Related Vulnerabilities
WordPress Plugin Nextend Google Connect Unspecified Vulnerability (1.5.3)
MySQL CVE-2015-4862 Vulnerability (CVE-2015-4862)
WordPress Plugin Royal Gallery Cross-Site Scripting (2.0)
WordPress Plugin Double Opt-In for Download SQL Injection (2.0.8)
WordPress Plugin WordPress Firewall 2 Multiple Vulnerabilities (1.3)