AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-44649

MEDIUM · CVSS 5.4 EPSS 0.62%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-01-12 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.4. It affects Java.

CVE
CVE-2021-44649
Severity
MEDIUM
CVSS
5.4
EPSS
0.62%
Java

Original NVD Description

Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cross Site Scripting (XSS) vulnerability. The vulnerability allows an attacker to execute arbitrary JavaScript code in the web browser of the affected user.

Related CVEs

Other vulnerabilities affecting the same vendor(s)