Show filters
5,504 Total Results
Displaying 391-400 of 5,504
Sort by:
Attacker Value
Unknown
CVE-2024-2354
Disclosure Date: March 10, 2024 (last updated February 27, 2025)
A vulnerability, which was classified as problematic, was found in Dreamer CMS 4.1.3. Affected is an unknown function of the file /admin/menu/toEdit. The manipulation of the argument id leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-256314 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-2179
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious code into the Name field which might be executed when users visit the affected page. The Concrete CMS security team gave this vulnerability a CVSS v3.1 score of 2.2 with a vector of AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N Concrete versions below 9 do not include group types so they are not affected by this vulnerability. Thanks Luca Fuda for reporting.
0
Attacker Value
Unknown
CVE-2024-27563
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.
0
Attacker Value
Unknown
CVE-2024-27561
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the installThemePlugin parameter.
0
Attacker Value
Unknown
CVE-2024-2001
Disclosure Date: February 29, 2024 (last updated February 26, 2025)
A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded.
0
Attacker Value
Unknown
CVE-2024-22939
Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.
0
Attacker Value
Unknown
CVE-2024-21726
Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Inadequate content filtering leads to XSS vulnerabilities in various components.
0
Attacker Value
Unknown
CVE-2024-21725
Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.
0
Attacker Value
Unknown
CVE-2024-21723
Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Inadequate parsing of URLs could result into an open redirect.
0
Attacker Value
Unknown
CVE-2024-21722
Disclosure Date: February 29, 2024 (last updated February 26, 2025)
The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.
0