Filtered by vendor Gougucms Subscriptions
Filtered by product Gougucms Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2023-46393 1 Gougucms 1 Gougucms 2023-11-07 7.5 High
gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' passwords via a crafted packet.
CVE-2023-46394 1 Gougucms 1 Gougucms 2023-11-03 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the headimgurl parameter.