7.1

CVSS4.0

CVE-2025-41096 - Insecure Direct Object Reference in GPS BOLD Workplanner

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to the dates of the current contract details using unauthorised internal identifie…

📅 Published: Sept. 30, 2025, 11:16 a.m. 🔄 Last Modified: Oct. 8, 2025, 6:18 p.m.

7.1

CVSS4.0

CVE-2025-41095 - Insecure Direct Object Reference in GPS BOLD Workplanner

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to planning counter details using unauthorised internal identifiers.

📅 Published: Sept. 30, 2025, 11:15 a.m. 🔄 Last Modified: Oct. 8, 2025, 6:18 p.m.

7.1

CVSS4.0

CVE-2025-41094 - Insecure Direct Object Reference in GPS BOLD Workplanner

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to functional contract details using unauthorised internal identifiers.

📅 Published: Sept. 30, 2025, 11:14 a.m. 🔄 Last Modified: Oct. 8, 2025, 6:18 p.m.

7.1

CVSS4.0

CVE-2025-41093 - Insecure Direct Object Reference in GPS BOLD Workplanner

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to basic contract details using unauthorised internal identifiers.

📅 Published: Sept. 30, 2025, 11:13 a.m. 🔄 Last Modified: Oct. 8, 2025, 6:17 p.m.

7.1

CVSS4.0

CVE-2025-41092 - Insecure Direct Object Reference in GPS BOLD Workplanner

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to time records details using unauthorised internal identifiers.

📅 Published: Sept. 30, 2025, 11:12 a.m. 🔄 Last Modified: Oct. 8, 2025, 6:16 p.m.

7.1

CVSS4.0

CVE-2025-41091 - Insecure Direct Object Reference in GPS BOLD Workplanner

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to calendar details using unauthorised internal identifiers.

📅 Published: Sept. 30, 2025, 11:10 a.m. 🔄 Last Modified: Oct. 8, 2025, 6:53 p.m.

8.7

CVSS4.0

CVE-2025-8122 - Blind SQL Injection in PAD CMS

Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This issue affects all 3 templates: www, bip and ww+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.

📅 Published: Sept. 30, 2025, 10:05 a.m. 🔄 Last Modified: Nov. 26, 2025, 2:36 p.m.

8.7

CVSS4.0

CVE-2025-8121 - Blind SQL Injection in PAD CMS

Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This issue affects all 3 templates: www, bip and ww+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.

📅 Published: Sept. 30, 2025, 10:05 a.m. 🔄 Last Modified: Nov. 26, 2025, 2:37 p.m.

10

CVSS4.0

CVE-2025-8120 - Remote Code Execution via Unrestricted File Upload in PAD CMS

Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can then be executed leading to Remote Code Execution.This issue affects all 3 templates: www, bip…

📅 Published: Sept. 30, 2025, 10:05 a.m. 🔄 Last Modified: Nov. 26, 2025, 2:37 p.m.

5.1

CVSS4.0

CVE-2025-8119 - Cross-Site Request Forgery in PAD CMS

PAD CMS is vulnerable to Cross-Site Request Forgery in reset password's functionality. Malicious attacker can craft special website, which when visited by the victim, will automatically send a POST request changing currently logged user's password to defined by the attacker value. This issue affect…

📅 Published: Sept. 30, 2025, 10:04 a.m. 🔄 Last Modified: Nov. 26, 2025, 2:40 p.m.
Total resulsts: 349182
Page 3630 of 34,919
« previous page » next page
Filters