Show filters
25 Total Results
Displaying 1-10 of 25
Sort by:
Attacker Value
Very High
CVE-2020-8135
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.
0
Attacker Value
Unknown
CVE-2025-24643
Disclosure Date: February 03, 2025 (last updated February 04, 2025)
Missing Authorization vulnerability in Amento Tech Pvt ltd WPGuppy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WPGuppy: from n/a through 1.1.0.
0
Attacker Value
Unknown
CVE-2024-56280
Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Incorrect Privilege Assignment vulnerability in Amento Tech Pvt ltd WPGuppy allows Privilege Escalation.This issue affects WPGuppy: from n/a through 1.1.0.
0
Attacker Value
Unknown
CVE-2024-49222
Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Deserialization of Untrusted Data vulnerability in Amento Tech Pvt ltd WPGuppy allows Object Injection.This issue affects WPGuppy: from n/a through 1.1.0.
0
Attacker Value
Unknown
CVE-2023-31903
Disclosure Date: May 17, 2023 (last updated October 08, 2023)
GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.
0
Attacker Value
Unknown
CVE-2022-3464
Disclosure Date: October 12, 2022 (last updated October 08, 2023)
A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-210699.
0
Attacker Value
Unknown
CVE-2022-0528
Disclosure Date: March 03, 2022 (last updated February 23, 2025)
Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.
0
Attacker Value
Unknown
CVE-2021-24997
Disclosure Date: December 27, 2021 (last updated February 23, 2025)
The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any user to call them and could lead to sensitive information disclosure, such as usernames and chats between users, as well as be able to send messages as an arbitrary user
0
Attacker Value
Unknown
CVE-2020-18890
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.
0
Attacker Value
Unknown
CVE-2020-18888
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php.
0