Show filters
25 Total Results
Displaying 1-10 of 25
Sort by:
Attacker Value
Very High

CVE-2020-8135

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.
Attacker Value
Unknown

CVE-2025-24643

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
Missing Authorization vulnerability in Amento Tech Pvt ltd WPGuppy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WPGuppy: from n/a through 1.1.0.
0
Attacker Value
Unknown

CVE-2024-56280

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Incorrect Privilege Assignment vulnerability in Amento Tech Pvt ltd WPGuppy allows Privilege Escalation.This issue affects WPGuppy: from n/a through 1.1.0.
0
Attacker Value
Unknown

CVE-2024-49222

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Deserialization of Untrusted Data vulnerability in Amento Tech Pvt ltd WPGuppy allows Object Injection.This issue affects WPGuppy: from n/a through 1.1.0.
0
Attacker Value
Unknown

CVE-2023-31903

Disclosure Date: May 17, 2023 (last updated October 08, 2023)
GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.
Attacker Value
Unknown

CVE-2022-3464

Disclosure Date: October 12, 2022 (last updated October 08, 2023)
A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-210699.
Attacker Value
Unknown

CVE-2022-0528

Disclosure Date: March 03, 2022 (last updated February 23, 2025)
Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.
Attacker Value
Unknown

CVE-2021-24997

Disclosure Date: December 27, 2021 (last updated February 23, 2025)
The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any user to call them and could lead to sensitive information disclosure, such as usernames and chats between users, as well as be able to send messages as an arbitrary user
Attacker Value
Unknown

CVE-2020-18890

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.
Attacker Value
Unknown

CVE-2020-18888

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php.