Known Vulnerabilities for products from Jahia
Listed below are 3 of the newest known vulnerabilities associated with the vendor "Jahia".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2013-4624 json | Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to inject arb... | Not Provided | 2013-11-27 | 2026-04-29 |
| CVE-2013-4617 json | Jahia xCM before 6.6.2 does not include the HTTPOnly flag in a Set-Cookie header for the JSESSIONID cookie, which makes it ea... | Not Provided | 2013-11-27 | 2026-04-29 |
| CVE-2013-3920 json | Cross-site scripting (XSS) vulnerability in Jahia xCM before 6.6.2 allows remote authenticated users to inject arbitrary web ... | Not Provided | 2013-11-27 | 2026-04-29 |
Known software with vulnerabilities from Jahia
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Jahia | Jahia Xcm | 6.6.1 |