Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2022-33098
Disclosure Date: July 07, 2022 (last updated February 24, 2025)
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
0
Attacker Value
Unknown
CVE-2021-46366
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials.
0
Attacker Value
Unknown
CVE-2021-46365
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.
0
Attacker Value
Unknown
CVE-2021-46364
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file.
0
Attacker Value
Unknown
CVE-2021-46363
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS files. These formulas may result in arbitrary code execution on a victim's computer when opening the exported files with Microsoft Excel.
0
Attacker Value
Unknown
CVE-2021-46362
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.
0
Attacker Value
Unknown
CVE-2021-46361
Disclosure Date: February 11, 2022 (last updated October 07, 2023)
An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload.
0
Attacker Value
Unknown
CVE-2021-25893
Disclosure Date: April 02, 2021 (last updated February 22, 2025)
Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/.
0
Attacker Value
Unknown
CVE-2021-25894
Disclosure Date: April 02, 2021 (last updated February 22, 2025)
Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the /magnoliaPublic/travel/members/login.html mgnlUserId parameter.
0
Attacker Value
Unknown
CVE-2013-4621
Disclosure Date: December 27, 2019 (last updated November 27, 2024)
Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities
0