Known CVE
CrafterCMS Engine - Cross-Site Scripting
CrafterCMS Engine is vulnerable to reflected cross-site scripting (XSS) via the transformerName parameter in the /api/1/site/url/transform endpoint, allowing attackers to execute arbitrary JavaScript in the context of the user.
CVE-2023-4136
Medium2023CVSS 6.1CWE-79
cve2023 · craftercms · xss · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website