Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Unknown

CVE-2024-22648

Disclosure Date: January 30, 2024 (last updated February 03, 2024)
A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to scan ports in the local environment.
Attacker Value
Unknown

CVE-2024-22647

Disclosure Date: January 30, 2024 (last updated February 03, 2024)
An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine if a username is valid or not, enabling a brute-force attack with valid usernames.
Attacker Value
Unknown

CVE-2024-22646

Disclosure Date: January 30, 2024 (last updated February 03, 2024)
An email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allows an attacker to guess which emails exist on the system.
Attacker Value
Unknown

CVE-2024-22643

Disclosure Date: January 30, 2024 (last updated February 03, 2024)
A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unauthorized user password resets.
Attacker Value
Unknown

CVE-2021-34117

Disclosure Date: February 15, 2023 (last updated February 24, 2025)
SQL Injection vulnerability in SEO Panel 4.9.0 in api/user.api.php in function getUserName in the username parameter, allows attackers to gain sensitive information.
Attacker Value
Unknown

CVE-2021-39413

Disclosure Date: November 05, 2021 (last updated February 23, 2025)
Multiple Cross Site Scripting (XSS) vulnerabilities exits in SEO Panel v4.8.0 via the (1) to_time parameter in (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php, (e) pagespeed.php, (f) rank.php, (g) review.php, (h) saturationchecker.php, (i) social_media.php, and (j) reports.php; the (2) from_time parameter in (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php, (e) pagespeed.php, (f) rank.php, (g) review.php, (h) saturationchecker.php, (i) social_media.php, (j) webmaster-tools.php, and (k) reports.php; the (3) order_col parameter in (a) analytics.php, (b) review.php, (c) social_media.php, and (d) webmaster-tools.php; and the (4) pageno parameter in (a) alerts.php, (b) log.php, (c) keywords.php, (d) proxy.php, (e) searchengine.php, and (f) siteauditor.php.
Attacker Value
Unknown

CVE-2020-27461

Disclosure Date: August 20, 2021 (last updated February 23, 2025)
A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution through an authenticated file upload via the Settings Panel>Import website function.
Attacker Value
Unknown

CVE-2021-29008

Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via webmaster-tools.php in the "to_time" parameter.
Attacker Value
Unknown

CVE-2021-29010

Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "report_type" parameter.
Attacker Value
Unknown

CVE-2021-29009

Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "type" parameter.