CVE-2024-44010: Catchthemes Full Frame
Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catchthemes Full frame full-frame allows Stored XSS.This issue affects Full frame: from n/a through <= 2.7.2.
Affected products
- Catchthemes Full Frame: before 2.7.3 (fixed in 2.7.3); before 4.3.1 (fixed in 4.3.1)
Published 2024-10-06. Last modified 2026-06-17.