Show filters
26 Total Results
Displaying 1-10 of 26
Sort by:
Attacker Value
Unknown

CVE-2024-38766

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Matomo Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: from n/a through 5.1.1.
0
Attacker Value
Unknown

CVE-2023-6923

Disclosure Date: February 29, 2024 (last updated February 29, 2024)
The Matomo Analytics – Ethical Stats. Powerful Insights. plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the idsite parameter in all versions up to, and including, 4.15.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown

CVE-2023-33211

Disclosure Date: May 28, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in André Bräkling WP-Matomo Integration (WP-Piwik) plugin <= 1.0.27 versions.
Attacker Value
Unknown

CVE-2022-33156

Disclosure Date: July 12, 2022 (last updated October 07, 2023)
The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3 allows XSS.
Attacker Value
Unknown

CVE-2020-29578

Disclosure Date: December 08, 2020 (last updated February 22, 2025)
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.
Attacker Value
Unknown

CVE-2013-0193

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0194 and CVE-2013-0195.
Attacker Value
Unknown

CVE-2013-0194

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0195.
Attacker Value
Unknown

CVE-2013-0195

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0194.
Attacker Value
Unknown

CVE-2019-12215

Disclosure Date: May 20, 2019 (last updated November 08, 2023)
A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to discover the full path of Matomo on the disk, because lastError.file is used in plugins/CorePluginsAdmin/templates/safemode.twig. NOTE: the vendor disputes the significance of this issue, stating "avoid reporting path disclosures, as we don't consider them as security vulnerabilities.
0
Attacker Value
Unknown

CVE-2015-7816

Disclosure Date: November 16, 2015 (last updated October 05, 2023)
The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object injection attacks, conduct Server-Side Request Forgery (SSRF) attacks, and execute arbitrary PHP code via a crafted HTTP header.
0