Vulnerability Database

321,672

Total vulnerabilities in the database

CVE-2020-37072

Victor CMS 1.0 contains a stored cross-site scripting vulnerability in the 'comment_author' POST parameter that allows attackers to inject malicious scripts. Attackers can submit crafted JavaScript payloads through the comment submission form to execute arbitrary code in victim browsers.

  • Published: Feb 3, 2026
  • Updated: Feb 4, 2026
  • CVE: CVE-2020-37072
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.2
  • AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N