Show filters
5,504 Total Results
Displaying 391-400 of 5,504
Sort by:
Attacker Value
Unknown

CVE-2024-2354

Disclosure Date: March 10, 2024 (last updated February 27, 2025)
A vulnerability, which was classified as problematic, was found in Dreamer CMS 4.1.3. Affected is an unknown function of the file /admin/menu/toEdit. The manipulation of the argument id leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-256314 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-2179

Disclosure Date: March 05, 2024 (last updated February 26, 2025)
Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious code into the Name field which might be executed when users visit the affected page. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 2.2 with a vector of AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N Concrete versions below 9 do not include group types so they are not affected by this vulnerability. Thanks Luca Fuda for reporting.
Attacker Value
Unknown

CVE-2024-27563

Disclosure Date: March 05, 2024 (last updated February 26, 2025)
A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.
Attacker Value
Unknown

CVE-2024-27561

Disclosure Date: March 05, 2024 (last updated February 26, 2025)
A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the installThemePlugin parameter.
Attacker Value
Unknown

CVE-2024-2001

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded.
0
Attacker Value
Unknown

CVE-2024-22939

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.
Attacker Value
Unknown

CVE-2024-21726

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Inadequate content filtering leads to XSS vulnerabilities in various components.
0
Attacker Value
Unknown

CVE-2024-21725

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.
0
Attacker Value
Unknown

CVE-2024-21723

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Inadequate parsing of URLs could result into an open redirect.
0
Attacker Value
Unknown

CVE-2024-21722

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.
0