monocms kayıtları
monocms üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-532 Insertion of Sensitive Information into Log File1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
33İzleyin | CVE-2020-25985İstismar yok | MonoCMS Blog 1.0 is affected by: Arbitrary File Deletion.monocms · monocms · CWE-22 | Yüksek8,1 | — | %1,7 | 7 Eki 2020 |
31İzleyin | CVE-2020-28672İstismar yok | MonoCMS Blog 1.0 is affected by incorrect access control that can lead to remote arbitrary code execution.monocms · monocms | Yüksek7,2 | — | %11,7 | 7 Oca 2021 |
30İzleyin | CVE-2020-25987İstismar yok | MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog.monocms · monocms · CWE-532 | Yüksek7,5 | — | %1,6 | 6 Eki 2020 |
26İzleyin | CVE-2020-25986İstismar yok | A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user.monocms · monocms · CWE-352 | Orta6,5 | — | %0,6 | 6 Eki 2020 |
21İzleyin | CVE-2024-10927İstismar yok | MonoCMS Account Information Page account.php cross site scriptingmonocms · monocms · CWE-74 | Orta5,3 | — | %0,4 | 6 Kas 2024 |
21İzleyin | CVE-2024-10928İstismar yok | MonoCMS Posts Page opensaved.php cross site scriptingmonocms · monocms · CWE-74 | Orta5,3 | — | %0,4 | 6 Kas 2024 |
- CVE-2020-2598533İzleyin
MonoCMS Blog 1.0 is affected by: Arbitrary File Deletion.
YüksekCVSS 8,1İstismar yokEPSS %2monocms · monocms7 Eki 2020
- CVE-2020-2867231İzleyin
MonoCMS Blog 1.0 is affected by incorrect access control that can lead to remote arbitrary code execution.
YüksekCVSS 7,2İstismar yokEPSS %12monocms · monocms7 Oca 2021
- CVE-2020-2598730İzleyin
MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog.
YüksekCVSS 7,5İstismar yokEPSS %2monocms · monocms6 Eki 2020
- CVE-2020-2598626İzleyin
A Cross Site Request Forgery (CSRF) vulnerability in MonoCMS Blog 1.0 allows attackers to change the password of a user.
OrtaCVSS 6,5İstismar yokEPSS %1monocms · monocms6 Eki 2020
- CVE-2024-1092721İzleyin
MonoCMS Account Information Page account.php cross site scripting
OrtaCVSS 5,3İstismar yokEPSS %0monocms · monocms6 Kas 2024
- CVE-2024-1092821İzleyin
MonoCMS Posts Page opensaved.php cross site scripting
OrtaCVSS 5,3İstismar yokEPSS %0monocms · monocms6 Kas 2024