CVE-2009-4168

Vulnérabilités

CVE-2009-4168

Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and…

MEDIUM Extension Joomla (identification incertaine) Pertinence : probable

Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags action. Cross-site scripting (XSS) vulnerability in tagcloud.swf in the WP-Cumulus Plug-in before 1.23 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter.

4.3 Moyenne · CVSS 2.0

AV:N/AC:M/Au:N/C:N/I:P/A:N

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDMEDIUM 4.3 (v2.0)
Produit
Extension Joomla (identification incertaine)
Corrigée dans
Non précisée
Publiée
02/12/2009
Modifiée
16/06/2026
CWE
CWE-79
  • wp-cumulus — jusqu'à 1.22
  • wp-cumulus — 1.00 – 1.00
  • wp-cumulus — 1.01 – 1.01
  • wp-cumulus — 1.02 – 1.02
  • wp-cumulus — 1.2.1 – 1.2.1
  • wp-cumulus — 1.03 – 1.03
  • wp-cumulus — 1.04 – 1.04
  • wp-cumulus — 1.05 – 1.05
  • wp-cumulus — 1.10 – 1.10
  • wp-cumulus — 1.11 – 1.11
  • wp-cumulus — 1.12 – 1.12
  • wp-cumulus — 1.13 – 1.13
7 autres
  • wp-cumulus — 1.14 – 1.14
  • wp-cumulus — 1.15 – 1.15
  • wp-cumulus — 1.16 – 1.16
  • wp-cumulus — 1.17 – 1.17
  • wp-cumulus — 1.18 – 1.18
  • wp-cumulus — 1.19 – 1.19
  • wp-cumulus — 1.20 – 1.20

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:27 UTC