📦

portfolio

Vendor: bixie

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 1 Total Indexed
Avg. EPSS 0.68% Exploit Prob.
Latest CVE CVE-2018-18087 Oct 09

Security Vulnerability Index

Page 1 / 1
5.4 CVSS

The Bixie Portfolio plugin 1.2.0 for Pagekit has XSS: a logged-in user who has the "Manage portfolio" privilege can inject arbitrary web script or HTML via the Image URL field in the portfolio editor. The vulnerability is triggered by visiting /portfolio/${project_title}.

EPSS: 0.68%