Filtered by vendor Kiamo Subscriptions
Filtered by product Kiamo Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-70364 1 Kiamo 1 Kiamo 2026-04-10 N/A
An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server.
CVE-2025-70365 1 Kiamo 1 Kiamo 2026-04-10 N/A
A stored cross-site scripting (XSS) vulnerability exists in Kiamo before 8.4 due to improper output encoding of user-supplied input in administrative interfaces. An authenticated administrative user can inject arbitrary JavaScript code that is executed in the browser of users viewing the affected pages.