ProjectPier records
9 published records for vendor projectpier.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-10759No exploit | PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbitprojectpier · projectpier · CWE-89 | Critical9.8 | — | 1.8% | May 16, 2018 |
35Monitor | CVE-2018-10760No exploit | Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbiprojectpier · projectpier · CWE-434 | High8.8 | — | 1.2% | May 16, 2018 |
27Monitor | CVE-2008-5583No exploit | Cross-site request forgery (CSRF) vulnerability in index.php in ProjectPier 0.8 and earlier allows remote attackers to perform actions as anprojectpier · projectpier · CWE-352 | Medium6.8 | — | 0.7% | Dec 15, 2008 |
24Monitor | CVE-2015-2796No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote attackers to inject arbitrary web script oprojectpier · projectpier · CWE-79 | Medium6.1 | — | 1.1% | Feb 2, 2018 |
21Monitor | CVE-2013-3636No exploit | ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flagprojectpier · projectpier · CWE-79 | Medium5.4 | — | 1.0% | Feb 7, 2020 |
21Monitor | CVE-2013-3635No exploit | ProjectPier 0.8.8 has stored XSSprojectpier · projectpier · CWE-79 | Medium5.4 | — | 0.6% | Feb 7, 2020 |
21Monitor | CVE-2013-3637No exploit | ProjectPier 0.8.8 does not use the Secure flag for cookiesprojectpier · projectpier · CWE-79 | Medium5.4 | — | 0.6% | Feb 7, 2020 |
20Monitor | CVE-2011-3797No exploit | ProjectPier 0.8.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installatprojectpier · projectpier · CWE-200 | Medium5.0 | — | 1.2% | Sep 23, 2011 |
18Monitor | CVE-2008-5584Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or projectpier · projectpier · CWE-79 | Medium4.3 | — | 3.0% | Dec 15, 2008 |
- CVE-2018-1075940Plan
PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbit
CriticalCVSS 9.8No exploitEPSS 2%projectpier · projectpierMay 16, 2018
- CVE-2018-1076035Monitor
Unrestricted file upload vulnerability in the Files plugin in ProjectPier 0.88 and earlier allows remote authenticated users to execute arbi
HighCVSS 8.8No exploitEPSS 1%projectpier · projectpierMay 16, 2018
- CVE-2008-558327Monitor
Cross-site request forgery (CSRF) vulnerability in index.php in ProjectPier 0.8 and earlier allows remote attackers to perform actions as an
MediumCVSS 6.8No exploitEPSS 1%projectpier · projectpierDec 15, 2008
- CVE-2015-279624Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote attackers to inject arbitrary web script o
MediumCVSS 6.1No exploitEPSS 1%projectpier · projectpierFeb 2, 2018
- CVE-2013-363621Monitor
ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag
MediumCVSS 5.4No exploitEPSS 1%projectpier · projectpierFeb 7, 2020
- CVE-2013-363521Monitor
ProjectPier 0.8.8 has stored XSS
MediumCVSS 5.4No exploitEPSS 1%projectpier · projectpierFeb 7, 2020
- CVE-2013-363721Monitor
ProjectPier 0.8.8 does not use the Secure flag for cookies
MediumCVSS 5.4No exploitEPSS 1%projectpier · projectpierFeb 7, 2020
- CVE-2011-379720Monitor
ProjectPier 0.8.0.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installat
MediumCVSS 5.0No exploitEPSS 1%projectpier · projectpierSep 23, 2011
- CVE-2008-558418Monitor
Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or
MediumCVSS 4.3Proof of conceptEPSS 3%projectpier · projectpierDec 15, 2008