Show filters
78 Total Results
Displaying 1-10 of 78
Sort by:
Attacker Value
Unknown

CVE-2025-22703

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in manuelvicedo Forge – Front-End Page Builder allows Stored XSS. This issue affects Forge – Front-End Page Builder: from n/a through 1.4.6.
0
Attacker Value
Unknown

CVE-2025-23027

Disclosure Date: January 13, 2025 (last updated January 14, 2025)
next-forge is a Next.js project boilerplate for modern web application. The BASEHUB_TOKEN commited in apps/web/.env.example. Users should avoid use of this token and should remove any access it may have in their systems.
0
Attacker Value
Unknown

CVE-2024-9160

Disclosure Date: September 27, 2024 (last updated September 28, 2024)
In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.
0
Attacker Value
Unknown

CVE-2024-31244

Disclosure Date: June 09, 2024 (last updated November 06, 2024)
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
Attacker Value
Unknown

CVE-2024-31243

Disclosure Date: June 09, 2024 (last updated November 06, 2024)
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
Attacker Value
Unknown

CVE-2024-31242

Disclosure Date: April 10, 2024 (last updated April 11, 2024)
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
0
Attacker Value
Unknown

CVE-2023-49948

Disclosure Date: December 03, 2023 (last updated December 08, 2023)
Forgejo before 1.20.5-1 allows remote attackers to test for the existence of private user accounts by appending .rss (or another extension) to a URL.
Attacker Value
Unknown

CVE-2023-49947

Disclosure Date: December 03, 2023 (last updated December 08, 2023)
Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication.
Attacker Value
Unknown

CVE-2023-49946

Disclosure Date: December 03, 2023 (last updated December 08, 2023)
In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform other unauthorized actions.
Attacker Value
Unknown

CVE-2023-32579

Disclosure Date: November 09, 2023 (last updated November 16, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Designs & Code Forget About Shortcode Buttons plugin <= 2.1.2 versions.