cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2014-8765,https://securityvulnerability.io/vulnerability/CVE-2014-8765,,"Multiple cross-site scripting (XSS) vulnerabilities in the Project Issue File Review module (PIFR) module 6.x-2.x before 6.x-2.17 for Drupal allow (1) remote attackers to inject arbitrary web script or HTML via a crafted patch, which triggers a PIFR client to test the patch and return the results to the PIFR_Server test results page or (2) remote authenticated users with the ""manage PIFR environments"" permission to inject arbitrary web script or HTML via vectors involving a PIFR_Server administrative page.",Drupal,Project Issue File Review,,,0.002199999988079071,false,,false,false,false,,,false,false,,2014-10-14T14:55:00.000Z,0