{"api_version":"1","generated_at":"2026-04-26T05:43:08+00:00","cve":"CVE-2014-5259","urls":{"html":"https://cve.report/CVE-2014-5259","api":"https://cve.report/api/cve/CVE-2014-5259.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-5259","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-5259"},"summary":{"title":"CVE-2014-5259","description":"Cross-site scripting (XSS) vulnerability in cattranslate.php in the CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2014-09-12 14:55:00","updated_at":"2018-10-09 19:50:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"http://forum.blackcat-cms.org/viewtopic.php?f=2&t=263","name":"http://forum.blackcat-cms.org/viewtopic.php?f=2&t=263","refsource":"CONFIRM","tags":["Patch"],"title":"Security Problem mit jQuery Plugin cattranslate - BlackCat CMS Forum","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.htbridge.com/advisory/HTB23228","name":"https://www.htbridge.com/advisory/HTB23228","refsource":"MISC","tags":["Exploit"],"title":"File Not Found","mime":"text/html","httpstatus":"404","archivestatus":"403"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95717","name":"blackcatcms-cve20145259-xss(95717)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/69551","name":"69551","refsource":"BID","tags":["Exploit"],"title":"BlackCat CMS 'cattranslate.php' Cross Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/533336/100/0/threaded","name":"20140903 Reflected Cross-Site Scripting (XSS) in BlackCat CMS","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/128141/BlackCat-CMS-1.0.3-Cross-Site-Scripting.html","name":"http://packetstormsecurity.com/files/128141/BlackCat-CMS-1.0.3-Cross-Site-Scripting.html","refsource":"MISC","tags":["Exploit"],"title":"BlackCat CMS 1.0.3 Cross Site Scripting ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-5259","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-5259","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"5259","vulnerable":"1","versionEndIncluding":"1.0.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"blackcat-cms","cpe5":"blackcat_cms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2014-5259","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in cattranslate.php in the CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20140903 Reflected Cross-Site Scripting (XSS) in BlackCat CMS","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/533336/100/0/threaded"},{"name":"69551","refsource":"BID","url":"http://www.securityfocus.com/bid/69551"},{"name":"http://forum.blackcat-cms.org/viewtopic.php?f=2&t=263","refsource":"CONFIRM","url":"http://forum.blackcat-cms.org/viewtopic.php?f=2&t=263"},{"name":"http://packetstormsecurity.com/files/128141/BlackCat-CMS-1.0.3-Cross-Site-Scripting.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/128141/BlackCat-CMS-1.0.3-Cross-Site-Scripting.html"},{"name":"https://www.htbridge.com/advisory/HTB23228","refsource":"MISC","url":"https://www.htbridge.com/advisory/HTB23228"},{"name":"blackcatcms-cve20145259-xss(95717)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95717"}]}},"nvd":{"publishedDate":"2014-09-12 14:55:00","lastModifiedDate":"2018-10-09 19:50:00","problem_types":["CWE-79"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:blackcat-cms:blackcat_cms:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"5259","Ordinal":"72247","Title":"CVE-2014-5259","CVE":"CVE-2014-5259","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"5259","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in cattranslate.php in the CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.","Type":"Description","Title":null},{"CveYear":"2014","CveId":"5259","Ordinal":"2","NoteData":"2014-09-12","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"5259","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}