Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/kielvaughn/cve-2021-38602
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityLearning & Education
GitHubkielvaughn/cve-2021-38602

CVE-2021-38602

View Repository
15 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-38602

A stored cross site scripting vulnerability is present on the Article editing page in version 5.8.7 of PluXML. User input is not properly sanitized in multiple fields.

Vulnerable Fields:

  • Headline (optional):
  • Content:

Create Article Page

Once inserted, XSS can be triggered by visiting the posted article at the link mentioned under Link to article: near the top of the page.

Link to Article

Headline Stored XSS Example


Headline XSS

Content Stored XSS Example


Content XSS

Download Tool