ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users and Search Pages function. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via injection of a crafted payload.
{ "nvd_published_at": "2022-10-31T12:15:00Z", "github_reviewed_at": "2022-11-01T21:38:06Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-79" ] }