Looking for the vulnerability index of Invicti's legacy products?
Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-27902 - Vulnerability Database

Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-27902

Medium
Reference: CVE-2021-27902
Title: Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

An issue was discovered in Craft CMS before 3.6.0. In some circumstances a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.