← Vulnerability feed

Vulnerability record · CVE-2008-1986 · published 27 April 2008

CVE-2008-1986: Pixel motion blog cross-site scripting vulnerability

Pixel Motion · Pixel Motion Blog

Cross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web script or HTML via the jours parameter.

4.3 CVSS 2.0 Medium EPSS 1.4% · top 27.9% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web script or HTML via the jours parameter.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-1986 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2008-1866Pixel motion blog code injection vulnerabilityadmin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to uploa…EPSS 5.2%7.5CVE-2008-1867Pixel motion blog sql injection vulnerabilitySQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL commands via the categorie p…EPSS 0.97%7.5CVE-2008-1868Pixel motion blog improper authentication vulnerabilityadmin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database b…EPSS 2.6%7.5CVE-2006-5085Blog Pixel Motion config.php static code injection enables PHP executionBlog Pixel Motion 2.1.1 writes the nom_blog parameter from config.php into include/variables.php without sanitization, allowing injected PHP code to …EPSS 47%analysed7.5CVE-2006-1426Pixel motion blog vulnerabilityMultiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in in…EPSS 2.0%6.4CVE-2006-5086Pixel motion blog vulnerabilityBlog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with m…EPSS 1.2%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed6.1CVE-2025-48700Zimbra Classic UI stored XSS via crafted email HTMLZimbra Collaboration Suite Classic UI fails to properly sanitize HTML content in email messages, allowing crafted tag structures and attribute values…KEVEPSS 1.7%analysed

Source: NIST National Vulnerability Database (record CVE-2008-1986), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.