Saurus operates a content management system that has surfaced a focused vulnerability profile centered on web application input handling. The recurring exposure involves cross-site scripting weaknesses in the Saurus CMS product, reflecting the input-validation demands common to web-facing publishing platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Saurus over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with "Article list" edit privileges, to inject arbitrary web scrip | May 20, 2010 | 2.1 | 19 | NO | YES |
CVE-2015-0876MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the print_language_selectbox function in classes/adminpage.inc.php in Saurus CMS Community Edition before 4.7 2015-02-04 allo | Apr 7, 2015 | 4.3 | 18 | NO | NO |
CVE-2015-1562MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Saurus CMS 4.7.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to admin/user_man | Feb 9, 2015 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Saurus.
Media articles that mention a CVE ID that affects a product developed by Saurus — matched by CVE ID, not by vendor name.