Enhavo is a content management and web application framework where reported vulnerabilities cluster around cross-site scripting (XSS) flaws, including both script-tag injection and HTML neutralization weaknesses typical of web-facing input handling. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Enhavo over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-25876MEDIUM A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into | Feb 22, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-25875MEDIUM A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into | Feb 22, 2024 | 6.1 | 18 | NO | NO |
CVE-2018-8832MEDIUM enhavo 0.4.0 has XSS via a user-group that contains executable JavaScript code in the user-group name. The XSS attack launches when a victim visits the admin user group page. | Mar 20, 2018 | 4.8 | 18 | NO | NO |
CVE-2024-25873MEDIUM Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote module. This vulnerability allows attackers to execute arbitr | Feb 22, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-25874MEDIUM A cross-site scripting (XSS) vulnerability in the New/Edit Article module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inje | Feb 22, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Enhavo.
Media articles that mention a CVE ID that affects a product developed by Enhavo — matched by CVE ID, not by vendor name.