← Back

Xt News

xt-news

Vendor: Dreaxteam • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dreaxteam
1Xt News
Apr 23, 2026
Dec 27, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in show_news.php in Xt-News 0.1 allows remote attackers to execute arbitrary SQL commands via the id_news parameter.
1Dreaxteam
1Xt News
Apr 23, 2026
Dec 27, 2006
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script or HTML via the id_news parameter to (1) add_comment.php or (2) show_news.php.