Pyrocms kayıtları
pyrocms üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-352 Cross-Site Request Forgery (CSRF)2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
55Planlayın | CVE-2023-29689Kavram kanıtı | PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw.pyrocms · pyrocms | Kritik9,8 | — | %53,5 | 4 Ağu 2023 |
36İzleyin | CVE-2022-37721İstismar yok | PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and japyrocms · pyrocms · CWE-79 | Kritik9,0 | — | %0,8 | 25 Kas 2022 |
28İzleyin | CVE-2020-25263İstismar yok | PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI: an arbitrary pluginpyrocms · pyrocms · CWE-352 | Yüksek7,1 | — | %0,6 | 8 Eki 2020 |
24İzleyin | CVE-2022-35118İstismar yok | PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.pyrocms · pyrocms · CWE-79 | Orta6,1 | — | %0,5 | 1 Ağu 2022 |
21İzleyin | CVE-2024-58297İstismar yok | PyroCMS v3.0.1 Stored Cross-Site Scripting via Admin Redirectspyrocms · pyrocms · CWE-79 | Orta5,3 | — | %0,3 | 11 Ara 2025 |
17İzleyin | CVE-2020-25262İstismar yok | PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/pages/delete/ URI: pages will be deleted.pyrocms · pyrocms · CWE-352 | Orta4,3 | — | %0,5 | 8 Eki 2020 |
- CVE-2023-2968955Planlayın
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw.
KritikCVSS 9,8Kavram kanıtıEPSS %53pyrocms · pyrocms4 Ağu 2023
- CVE-2022-3772136İzleyin
PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and ja
KritikCVSS 9,0İstismar yokEPSS %1pyrocms · pyrocms25 Kas 2022
- CVE-2020-2526328İzleyin
PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI: an arbitrary plugin
YüksekCVSS 7,1İstismar yokEPSS %1pyrocms · pyrocms8 Eki 2020
- CVE-2022-3511824İzleyin
PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
OrtaCVSS 6,1İstismar yokEPSS %1pyrocms · pyrocms1 Ağu 2022
- CVE-2024-5829721İzleyin
PyroCMS v3.0.1 Stored Cross-Site Scripting via Admin Redirects
OrtaCVSS 5,3İstismar yokEPSS %0pyrocms · pyrocms11 Ara 2025
- CVE-2020-2526217İzleyin
PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/pages/delete/ URI: pages will be deleted.
OrtaCVSS 4,3İstismar yokEPSS %1pyrocms · pyrocms8 Eki 2020