6.5

CVSS4.0

CVE-2025-66472 - XWiki vulnerable to a reflected XSS via xredirect parameter in DeleteApplication

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-milestone-1 through 16.10.9 and 17.0.0-rc-1 through 17.4.1 of both XWiki Platform Flamingo Skin Resources and XWiki Platform Web Templates are vulnerable to a reflected XSS attack …

📅 Published: Dec. 10, 2025, 9:34 p.m. 🔄 Last Modified: Feb. 18, 2026, 3:57 p.m.

5.3

CVSS4.0

CVE-2024-58285 - Chyrp 2.5.2 Stored Cross-Site Scripting Vulnerability via Post Title

Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into post titles. Attackers can craft payloads in the title field that will execute when the post is viewed by other users, potentially stealing session cookies or performing…

📅 Published: Dec. 10, 2025, 9:15 p.m. 🔄 Last Modified: March 5, 2026, 12:03 p.m.

8.6

CVSS4.0

CVE-2024-58284 - PopojiCMS 2.0.1 Remote Command Execution via Authenticated Metadata Settings

PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can log in and modify the meta content to create a web shell that executes arbitrary system commands throu…

📅 Published: Dec. 10, 2025, 9:15 p.m. 🔄 Last Modified: April 7, 2026, 2:08 p.m.

8.7

CVSS4.0

CVE-2024-58283 - WBCE CMS 1.6.2 Remote Code Execution via Elfinder File Upload

WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager. Attackers can exploit the file upload functionality in the elfinder connector to upload a web shell and execute arbitrary system…

📅 Published: Dec. 10, 2025, 9:14 p.m. 🔄 Last Modified: April 7, 2026, 2:08 p.m.

8.6

CVSS4.0

CVE-2024-58282 - Serendipity 2.5.0 Remote Code Execution via Authenticated Media Upload

Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload mechanism by creating a PHP shell with a command execution form that enables arbitrar…

📅 Published: Dec. 10, 2025, 9:14 p.m. 🔄 Last Modified: April 7, 2026, 2:08 p.m.

8.7

CVSS4.0

CVE-2024-58281 - Dotclear 2.29 Remote Code Execution via Authenticated File Upload

Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload process by crafting a PHP shell with a command execution form to gain system access through th…

📅 Published: Dec. 10, 2025, 9:13 p.m. 🔄 Last Modified: April 7, 2026, 2:08 p.m.

8.6

CVSS4.0

CVE-2024-58280 - CMSimple 5.15 Remote Command Execution via Extensions Configuration

CMSimple 5.15 contains a remote command execution vulnerability that allows authenticated attackers to modify file extensions and upload malicious PHP files. Attackers can append ',php' to Extensions_userfiles and upload a shell script to the media directory to execute arbitrary code on the server.

📅 Published: Dec. 10, 2025, 9:13 p.m. 🔄 Last Modified: April 7, 2026, 2:08 p.m.

8.6

CVSS4.0

CVE-2024-58279 - appRain CMF 4.0.5 Authenticated Remote Code Execution via Filemanager Upload

appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to upload malicious PHP files through the filemanager upload endpoint. Attackers can leverage authenticated access to generate a web shell with command execution capabilities by uploadin…

📅 Published: Dec. 10, 2025, 9:12 p.m. 🔄 Last Modified: April 7, 2026, 2:08 p.m.

8.7

CVSS4.0

CVE-2023-53776 - Screen SFT DAB 1.9.3 Authentication Bypass via Session Management Weakness

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to exploit weak session management by reusing IP-bound session identifiers. Attackers can issue unauthorized requests to the device management API by leveraging the session binding mechanism to perform critic…

📅 Published: Dec. 10, 2025, 9:12 p.m. 🔄 Last Modified: April 7, 2026, 2:06 p.m.

7.1

CVSS4.0

CVE-2023-53775 - Screen SFT DAB 1.9.3 Authentication Bypass via Session Management Weakness

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse IP-bound session identifiers to issue unauthorized requests to the userManager API and modify user credentials with…

📅 Published: Dec. 10, 2025, 9:08 p.m. 🔄 Last Modified: April 7, 2026, 2:06 p.m.
Total resulsts: 345248
Page 2281 of 34,525
« previous page » next page
Filters