flusity kayıtları
flusity üreticisine ait 28 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)13
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-269 Improper Privilege Management1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
28 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2024-31666Kavram kanıtı | An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component.flusity · flusity · CWE-94 | Kritik9,8 | — | %1,7 | 22 Nis 2024 |
39İzleyin | CVE-2024-25502İstismar yok | Directory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sensitive information vflusity · flusity · CWE-94 | Kritik9,8 | — | %1,4 | 15 Şub 2024 |
39İzleyin | CVE-2024-32418İstismar yok | An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.flusity · flusity · CWE-269 | Kritik9,8 | — | %1,1 | 21 Nis 2024 |
35İzleyin | CVE-2023-5812İstismar yok | flusity CMS upload.php handleFileUpload unrestricted uploadflusity · flusity · CWE-434 | Yüksek8,8 | — | %0,7 | 26 Eki 2023 |
35İzleyin | CVE-2024-24524İstismar yok | Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the add_menu.phflusity · flusity · CWE-352 | Yüksek8,8 | — | %0,5 | 2 Şub 2024 |
35İzleyin | CVE-2024-24470İstismar yok | Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php coflusity · flusity · CWE-352 | Yüksek8,8 | — | %0,5 | 2 Şub 2024 |
35İzleyin | CVE-2024-24469İstismar yok | Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.flusity · flusity · CWE-352 | Yüksek8,8 | — | %0,5 | 5 Şub 2024 |
35İzleyin | CVE-2024-24468İstismar yok | Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_customblock.phflusity · flusity · CWE-352 | Yüksek8,8 | — | %0,5 | 5 Şub 2024 |
35İzleyin | CVE-2024-25419İstismar yok | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_menu.php.flusity · flusity · CWE-352 | Yüksek8,8 | — | %0,3 | 11 Şub 2024 |
35İzleyin | CVE-2024-25418İstismar yok | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_menu.php.flusity · flusity · CWE-352 | Yüksek8,8 | — | %0,3 | 11 Şub 2024 |
35İzleyin | CVE-2024-26352İstismar yok | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_places.phpflusity · flusity · CWE-352 | Yüksek8,8 | — | %0,3 | 22 Şub 2024 |
35İzleyin | CVE-2024-26350İstismar yok | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_contact_form_settings.pflusity · flusity · CWE-352 | Yüksek8,8 | — | %0,3 | 22 Şub 2024 |
35İzleyin | CVE-2024-25417İstismar yok | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_translation.php.flusity · flusity · CWE-352 | Yüksek8,8 | — | %0,3 | 11 Şub 2024 |
35İzleyin | CVE-2024-23094İstismar yok | Flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /cover/addons/info_media_gallery/action/edflusity · flusity · CWE-352 | Yüksek8,8 | — | %0,3 | 22 Şub 2024 |
26İzleyin | CVE-2024-25410İstismar yok | flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php.flusity · flusity · CWE-434 | Orta6,5 | — | %0,6 | 26 Şub 2024 |
24İzleyin | CVE-2024-26491İstismar yok | A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Media Gallery with description' module of flusity-CMS v2.33 allows attacflusity · flusity · CWE-79 | Orta6,1 | — | %0,4 | 22 Şub 2024 |
24İzleyin | CVE-2024-27757İstismar yok | flusity CMS through 2.45 allows tools/addons_model.php Gallery Name XSS.flusity · flusity · CWE-79 | Orta6,1 | — | %0,4 | 18 Mar 2024 |
24İzleyin | CVE-2024-26489İstismar yok | A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Social block links' module of flusity-CMS v2.33 allows attackers to execflusity · flusity · CWE-79 | Orta6,1 | — | %0,4 | 22 Şub 2024 |
24İzleyin | CVE-2024-27668İstismar yok | Flusity-CMS v2.33 is affected by: Cross Site Scripting (XSS) in 'Custom Blocks.'flusity · flusity · CWE-79 | Orta6,1 | — | %0,4 | 4 Mar 2024 |
24İzleyin | CVE-2024-27680İstismar yok | Flusity-CMS v2.33 is vulnerable to Cross Site Scripting (XSS) in the "Contact form."flusity · flusity · CWE-79 | Orta6,1 | — | %0,4 | 4 Mar 2024 |
24İzleyin | CVE-2024-26445İstismar yok | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_place.phpflusity · flusity · CWE-352 | Orta6,1 | — | %0,2 | 22 Şub 2024 |
24İzleyin | CVE-2024-26351İstismar yok | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_place.phpflusity · flusity · CWE-352 | Orta6,1 | — | %0,2 | 22 Şub 2024 |
21İzleyin | CVE-2023-5793İstismar yok | flusity CMS Dashboard customblock.php loadCustomBlocCreateForm cross site scriptingflusity · flusity · CWE-79 | Orta5,4 | — | %0,4 | 26 Eki 2023 |
21İzleyin | CVE-2024-26490İstismar yok | A cross-site scripting (XSS) vulnerability in the Addon JD Simple module of flusity-CMS v2.33 allows attackers to execute arbitrary web scriflusity · flusity · CWE-79 | Orta5,4 | — | %0,4 | 22 Şub 2024 |
19İzleyin | CVE-2023-5811İstismar yok | flusity CMS posts.php loadPostAddForm cross site scriptingflusity · flusity · CWE-79 | Orta4,8 | — | %0,5 | 26 Eki 2023 |
- CVE-2024-3166640Planlayın
An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component.
KritikCVSS 9,8Kavram kanıtıEPSS %2flusity · flusity22 Nis 2024
- CVE-2024-2550239İzleyin
Directory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sensitive information v
KritikCVSS 9,8İstismar yokEPSS %1flusity · flusity15 Şub 2024
- CVE-2024-3241839İzleyin
An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.
KritikCVSS 9,8İstismar yokEPSS %1flusity · flusity21 Nis 2024
- CVE-2023-581235İzleyin
flusity CMS upload.php handleFileUpload unrestricted upload
YüksekCVSS 8,8İstismar yokEPSS %1flusity · flusity26 Eki 2023
- CVE-2024-2452435İzleyin
Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the add_menu.ph
YüksekCVSS 8,8İstismar yokEPSS %1flusity · flusity2 Şub 2024
- CVE-2024-2447035İzleyin
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php co
YüksekCVSS 8,8İstismar yokEPSS %1flusity · flusity2 Şub 2024
- CVE-2024-2446935İzleyin
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.
YüksekCVSS 8,8İstismar yokEPSS %1flusity · flusity5 Şub 2024
- CVE-2024-2446835İzleyin
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_customblock.ph
YüksekCVSS 8,8İstismar yokEPSS %0flusity · flusity5 Şub 2024
- CVE-2024-2541935İzleyin
flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_menu.php.
YüksekCVSS 8,8İstismar yokEPSS %0flusity · flusity11 Şub 2024
- CVE-2024-2541835İzleyin
flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_menu.php.
YüksekCVSS 8,8İstismar yokEPSS %0flusity · flusity11 Şub 2024
- CVE-2024-2635235İzleyin
flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_places.php
YüksekCVSS 8,8İstismar yokEPSS %0flusity · flusity22 Şub 2024
- CVE-2024-2635035İzleyin
flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_contact_form_settings.p
YüksekCVSS 8,8İstismar yokEPSS %0flusity · flusity22 Şub 2024
- CVE-2024-2541735İzleyin
flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_translation.php.
YüksekCVSS 8,8İstismar yokEPSS %0flusity · flusity11 Şub 2024
- CVE-2024-2309435İzleyin
Flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /cover/addons/info_media_gallery/action/ed
YüksekCVSS 8,8İstismar yokEPSS %0flusity · flusity22 Şub 2024
- CVE-2024-2541026İzleyin
flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php.
OrtaCVSS 6,5İstismar yokEPSS %1flusity · flusity26 Şub 2024
- CVE-2024-2649124İzleyin
A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Media Gallery with description' module of flusity-CMS v2.33 allows attac
OrtaCVSS 6,1İstismar yokEPSS %0flusity · flusity22 Şub 2024
- CVE-2024-2775724İzleyin
flusity CMS through 2.45 allows tools/addons_model.php Gallery Name XSS.
OrtaCVSS 6,1İstismar yokEPSS %0flusity · flusity18 Mar 2024
- CVE-2024-2648924İzleyin
A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Social block links' module of flusity-CMS v2.33 allows attackers to exec
OrtaCVSS 6,1İstismar yokEPSS %0flusity · flusity22 Şub 2024
- CVE-2024-2766824İzleyin
Flusity-CMS v2.33 is affected by: Cross Site Scripting (XSS) in 'Custom Blocks.'
OrtaCVSS 6,1İstismar yokEPSS %0flusity · flusity4 Mar 2024
- CVE-2024-2768024İzleyin
Flusity-CMS v2.33 is vulnerable to Cross Site Scripting (XSS) in the "Contact form."
OrtaCVSS 6,1İstismar yokEPSS %0flusity · flusity4 Mar 2024
- CVE-2024-2644524İzleyin
flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_place.php
OrtaCVSS 6,1İstismar yokEPSS %0flusity · flusity22 Şub 2024
- CVE-2024-2635124İzleyin
flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_place.php
OrtaCVSS 6,1İstismar yokEPSS %0flusity · flusity22 Şub 2024
- CVE-2023-579321İzleyin
flusity CMS Dashboard customblock.php loadCustomBlocCreateForm cross site scripting
OrtaCVSS 5,4İstismar yokEPSS %0flusity · flusity26 Eki 2023
- CVE-2024-2649021İzleyin
A cross-site scripting (XSS) vulnerability in the Addon JD Simple module of flusity-CMS v2.33 allows attackers to execute arbitrary web scri
OrtaCVSS 5,4İstismar yokEPSS %0flusity · flusity22 Şub 2024
- CVE-2023-581119İzleyin
flusity CMS posts.php loadPostAddForm cross site scripting
OrtaCVSS 4,8İstismar yokEPSS %1flusity · flusity26 Eki 2023