CVE-2024-30880: Rageframe
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Reflected Cross Site Scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted payload injected into the multiple parameter in the image cropping function.
Affected products
- Rageframe Rageframe: version 2.6.43 only
Published 2024-04-11. Last modified 2026-06-17.