Jahia
3 CVEs tracked since 2013. Since Nov 2013, none of them reached CISA KEV.
Jahia CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2013-11 | 3 | 0 |
Products
The products that kept showing up in Jahia's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 3 most recently published vulnerabilities affecting Jahia.
- CVE-2013-3920Cross-site scripting (XSS) vulnerability in Jahia xCM before 6.6.2 allows remote authenticated users to inject arbitrary web script or HTML via the "about me" field.3.5
- CVE-2013-4624Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to inject arbitrary web script or HTML via (1) the site parameter to engines/manager....4.3
- CVE-2013-4617Jahia xCM before 6.6.2 does not include the HTTPOnly flag in a Set-Cookie header for the JSESSIONID cookie, which makes it easier for remote attackers to obtain potentially sensitive information vi...5.0
The record
- Peak rank
- #35 in Nov 2013
- Busiest month shown
- Nov 2013, 3 CVEs
- Months with a KEV entry
- 0 since Nov 2013
- Monthly snapshots
- 1 since 2013