Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Very High
CVE-2020-8135
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.
0
Attacker Value
Unknown
CVE-2023-31903
Disclosure Date: May 17, 2023 (last updated February 25, 2025)
GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.
0
Attacker Value
Unknown
CVE-2022-3464
Disclosure Date: October 12, 2022 (last updated February 24, 2025)
A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-210699.
0
Attacker Value
Unknown
CVE-2021-24997
Disclosure Date: December 27, 2021 (last updated February 23, 2025)
The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any user to call them and could lead to sensitive information disclosure, such as usernames and chats between users, as well as be able to send messages as an arbitrary user
0
Attacker Value
Unknown
CVE-2020-18890
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.
0
Attacker Value
Unknown
CVE-2020-18888
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php.
0
Attacker Value
Unknown
CVE-2020-18889
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/settings.php.
0
Attacker Value
Unknown
CVE-2018-15847
Disclosure Date: August 25, 2018 (last updated November 27, 2024)
An issue was discovered in puppyCMS 5.1. There is an XSS vulnerability via menu.php in the "Add Page/URL" URL link field.
0
Attacker Value
Unknown
CVE-2013-5983
Disclosure Date: February 06, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in GuppY before 4.6.28 allow remote attackers to inject arbitrary web script or HTML via the (1) "an" parameter to agenda.php or (2) cat parameter to mobile/thread.php.
0
Attacker Value
Unknown
CVE-2010-1740
Disclosure Date: May 06, 2010 (last updated October 04, 2023)
SQL injection vulnerability in newsletter.php in GuppY 4.5.18 allows remote attackers to execute arbitrary SQL commands via the lng parameter.
0