matomo kayıtları
matomo üreticisine ait 25 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %4
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %20
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-20 Improper Input Validation2
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
25 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
53Planlayın | CVE-2009-4140Silahlaştırılmış | Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0teethgrinder.co.uk · open flash chart | Yüksek7,5 | — | %75,8 | 22 Ara 2009 |
40Planlayın | CVE-2020-29578İstismar yok | The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user.matomo · piwik fpm-alpine docker image | Kritik9,8 | — | %2,3 | 8 Ara 2020 |
35İzleyin | CVE-2009-4137Kavram kanıtı | The loadContentFromCookie function in core/Cookie.php in Piwik before 0.5 does not validate strings obtained from cookies before calling thematomo · matomo · CWE-20 | Yüksek7,5 | — | %16,9 | 24 Ara 2009 |
31İzleyin | CVE-2015-7816İstismar yok | The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object injmatomo · matomo | Yüksek7,5 | — | %3,9 | 16 Kas 2015 |
31İzleyin | CVE-2015-7815İstismar yok | Directory traversal vulnerability in core/ViewDataTable/Factory.php in Piwik before 2.15.0 allows remote attackers to include and execute armatomo · matomo · CWE-22 | Yüksek7,5 | — | %3,0 | 16 Kas 2015 |
28İzleyin | CVE-2010-2786İstismar yok | Directory traversal vulnerability in Piwik 0.6 through 0.6.3 allows remote attackers to include arbitrary local files and possibly have unspmatomo · matomo · CWE-22 | Orta6,8 | — | %2,7 | 2 Ağu 2010 |
28İzleyin | CVE-2011-4941İstismar yok | Unspecified vulnerability in Piwik 1.2 through 1.4 allows remote attackers with the view permission to execute arbitrary code via unknown atmatomo · matomo | Orta6,8 | — | %2,3 | 18 Eyl 2012 |
25İzleyin | CVE-2011-0398İstismar yok | The Piwik_Common::getIP function in Piwik before 1.1 does not properly determine the client IP address, which allows remote attackers to bypmatomo · matomo · CWE-264 | Orta6,4 | — | %1,3 | 10 Oca 2011 |
24İzleyin | CVE-2013-0195İstismar yok | Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.matomo · matomo · CWE-79 | Orta6,1 | — | %1,2 | 20 Kas 2019 |
24İzleyin | CVE-2013-0194İstismar yok | Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.matomo · matomo · CWE-79 | Orta6,1 | — | %1,2 | 20 Kas 2019 |
24İzleyin | CVE-2013-0193İstismar yok | Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.matomo · matomo · CWE-79 | Orta6,1 | — | %1,2 | 20 Kas 2019 |
24İzleyin | CVE-2022-33156İstismar yok | The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3 allows XSS.matomo · integration · CWE-79 | Orta6,1 | — | %0,6 | 12 Tem 2022 |
24İzleyin | CVE-2023-6923İstismar yok | Matomo <= 4.15.3 - Reflected Cross-Site Scripting via idsitematomo · matomo · CWE-79 | Orta6,1 | — | %0,5 | 28 Şub 2024 |
20İzleyin | CVE-2011-0401İstismar yok | Piwik before 1.1 does not properly limit the number of files stored under tmp/sessions/, which might allow remote attackers to cause a deniamatomo · matomo · CWE-264 | Orta5,0 | — | %1,7 | 10 Oca 2011 |
20İzleyin | CVE-2011-0400İstismar yok | Cookie.php in Piwik before 1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attmatomo · matomo · CWE-16 | Orta5,0 | — | %1,3 | 10 Oca 2011 |
20İzleyin | CVE-2011-3791İstismar yok | Piwik 1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path imatomo · matomo · CWE-200 | Orta5,0 | — | %1,2 | 23 Eyl 2011 |
20İzleyin | CVE-2009-1085İstismar yok | Piwik 0.2.32 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to matomo · matomo · CWE-264 | Orta5,0 | — | %1,2 | 25 Mar 2009 |
20İzleyin | CVE-2013-2633İstismar yok | Piwik before 1.11 accepts input from a POST request instead of a GET request in unspecified circumstances, which might allow attackers to obmatomo · matomo · CWE-20 | Orta5,0 | — | %1,0 | 21 Mar 2013 |
19İzleyin | CVE-2025-4415İstismar yok | Piwik PRO - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-058matomo · piwik pro · CWE-79 | Orta4,8 | — | %0,2 | 21 May 2025 |
18İzleyin | CVE-2010-1453Kavram kanıtı | Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web scripiwik · piwik · CWE-79 | Orta4,3 | — | %3,0 | 7 May 2010 |
17İzleyin | CVE-2011-0004İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Piwik before 1.1 allow remote attackers to inject arbitrary web script or HTML via unmatomo · matomo · CWE-79 | Orta4,3 | — | %1,6 | 10 Oca 2011 |
17İzleyin | CVE-2011-0399İstismar yok | Piwik before 1.1 does not prevent the rendering of the login form inside a frame in a third-party HTML document, which makes it easier for rmatomo · matomo | Orta4,3 | — | %1,4 | 10 Oca 2011 |
17İzleyin | CVE-2019-12215İstismar yok | A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to discover the full path omatomo · matomo · CWE-209 | Orta4,3 | — | %1,2 | 20 May 2019 |
17İzleyin | CVE-2012-4541İstismar yok | Cross-site scripting (XSS) vulnerability in Piwik before 1.9 allows remote attackers to inject arbitrary web script or HTML via unspecified matomo · matomo · CWE-79 | Orta4,3 | — | %1,1 | 19 Kas 2012 |
17İzleyin | CVE-2013-1844İstismar yok | Cross-site scripting (XSS) vulnerability in Piwik before 1.11 allows remote attackers to inject arbitrary web script or HTML via unspecifiedmatomo · matomo · CWE-79 | Orta4,3 | — | %0,9 | 21 Mar 2013 |
- CVE-2009-414053Planlayın
Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0
YüksekCVSS 7,5SilahlaştırılmışEPSS %76teethgrinder.co.uk · open flash chart22 Ara 2009
- CVE-2020-2957840Planlayın
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user.
KritikCVSS 9,8İstismar yokEPSS %2matomo · piwik fpm-alpine docker image8 Ara 2020
- CVE-2009-413735İzleyin
The loadContentFromCookie function in core/Cookie.php in Piwik before 0.5 does not validate strings obtained from cookies before calling the
YüksekCVSS 7,5Kavram kanıtıEPSS %17matomo · matomo24 Ara 2009
- CVE-2015-781631İzleyin
The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object inj
YüksekCVSS 7,5İstismar yokEPSS %4matomo · matomo16 Kas 2015
- CVE-2015-781531İzleyin
Directory traversal vulnerability in core/ViewDataTable/Factory.php in Piwik before 2.15.0 allows remote attackers to include and execute ar
YüksekCVSS 7,5İstismar yokEPSS %3matomo · matomo16 Kas 2015
- CVE-2010-278628İzleyin
Directory traversal vulnerability in Piwik 0.6 through 0.6.3 allows remote attackers to include arbitrary local files and possibly have unsp
OrtaCVSS 6,8İstismar yokEPSS %3matomo · matomo2 Ağu 2010
- CVE-2011-494128İzleyin
Unspecified vulnerability in Piwik 1.2 through 1.4 allows remote attackers with the view permission to execute arbitrary code via unknown at
OrtaCVSS 6,8İstismar yokEPSS %2matomo · matomo18 Eyl 2012
- CVE-2011-039825İzleyin
The Piwik_Common::getIP function in Piwik before 1.1 does not properly determine the client IP address, which allows remote attackers to byp
OrtaCVSS 6,4İstismar yokEPSS %1matomo · matomo10 Oca 2011
- CVE-2013-019524İzleyin
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
OrtaCVSS 6,1İstismar yokEPSS %1matomo · matomo20 Kas 2019
- CVE-2013-019424İzleyin
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
OrtaCVSS 6,1İstismar yokEPSS %1matomo · matomo20 Kas 2019
- CVE-2013-019324İzleyin
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
OrtaCVSS 6,1İstismar yokEPSS %1matomo · matomo20 Kas 2019
- CVE-2022-3315624İzleyin
The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3 allows XSS.
OrtaCVSS 6,1İstismar yokEPSS %1matomo · integration12 Tem 2022
- CVE-2023-692324İzleyin
Matomo <= 4.15.3 - Reflected Cross-Site Scripting via idsite
OrtaCVSS 6,1İstismar yokEPSS %1matomo · matomo28 Şub 2024
- CVE-2011-040120İzleyin
Piwik before 1.1 does not properly limit the number of files stored under tmp/sessions/, which might allow remote attackers to cause a denia
OrtaCVSS 5,0İstismar yokEPSS %2matomo · matomo10 Oca 2011
- CVE-2011-040020İzleyin
Cookie.php in Piwik before 1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote att
OrtaCVSS 5,0İstismar yokEPSS %1matomo · matomo10 Oca 2011
- CVE-2011-379120İzleyin
Piwik 1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path i
OrtaCVSS 5,0İstismar yokEPSS %1matomo · matomo23 Eyl 2011
- CVE-2009-108520İzleyin
Piwik 0.2.32 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to
OrtaCVSS 5,0İstismar yokEPSS %1matomo · matomo25 Mar 2009
- CVE-2013-263320İzleyin
Piwik before 1.11 accepts input from a POST request instead of a GET request in unspecified circumstances, which might allow attackers to ob
OrtaCVSS 5,0İstismar yokEPSS %1matomo · matomo21 Mar 2013
- CVE-2025-441519İzleyin
Piwik PRO - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-058
OrtaCVSS 4,8İstismar yokEPSS %0matomo · piwik pro21 May 2025
- CVE-2010-145318İzleyin
Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web scri
OrtaCVSS 4,3Kavram kanıtıEPSS %3piwik · piwik7 May 2010
- CVE-2011-000417İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Piwik before 1.1 allow remote attackers to inject arbitrary web script or HTML via un
OrtaCVSS 4,3İstismar yokEPSS %2matomo · matomo10 Oca 2011
- CVE-2011-039917İzleyin
Piwik before 1.1 does not prevent the rendering of the login form inside a frame in a third-party HTML document, which makes it easier for r
OrtaCVSS 4,3İstismar yokEPSS %1matomo · matomo10 Oca 2011
- CVE-2019-1221517İzleyin
A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to discover the full path o
OrtaCVSS 4,3İstismar yokEPSS %1matomo · matomo20 May 2019
- CVE-2012-454117İzleyin
Cross-site scripting (XSS) vulnerability in Piwik before 1.9 allows remote attackers to inject arbitrary web script or HTML via unspecified
OrtaCVSS 4,3İstismar yokEPSS %1matomo · matomo19 Kas 2012
- CVE-2013-184417İzleyin
Cross-site scripting (XSS) vulnerability in Piwik before 1.11 allows remote attackers to inject arbitrary web script or HTML via unspecified
OrtaCVSS 4,3İstismar yokEPSS %1matomo · matomo21 Mar 2013