Записи Webedition
8 опубликованных записей вендора webedition.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2014-2302Эксплойта нет | The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attwebedition · webedition cms · CWE-94 | Критическая9,8 | — | 4,5 % | 19 июл. 2018 г. |
34Наблюдать | CVE-2023-53883Эксплойта нет | Webedition CMS v2.9.8.8 Remote Code Execution via PHP Page Creationwebedition · webedition cms · CWE-94 | Высокая8,6 | — | 1,0 % | 15 дек. 2025 г. |
31Наблюдать | CVE-2014-2303Proof of concept | Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8webedition · webedition cms · CWE-89 | Высокая7,5 | — | 2,6 % | 13 июн. 2014 г. |
26Наблюдать | CVE-2024-28418Эксплойта нет | Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.phpwebedition · webedition cms · CWE-434 | Средняя6,5 | — | 0,4 % | 14 мар. 2024 г. |
25Наблюдать | CVE-2024-28417Эксплойта нет | Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.webedition · webedition cms · CWE-80 | Средняя6,3 | — | 0,3 % | 14 мар. 2024 г. |
22Наблюдать | CVE-2014-5258Proof of concept | Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitrwebedition · webedition cms · CWE-22 | Средняя4,0 | — | 20,3 % | 6 нояб. 2014 г. |
21Наблюдать | CVE-2009-1222Proof of concept | Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and magic_quotes_gpc is dwebedition · webedition · CWE-22 | Средняя5,1 | — | 2,0 % | 2 апр. 2009 г. |
20Наблюдать | CVE-2023-53884Эксплойта нет | Webedition CMS v2.9.8.8 Stored Cross-Site Scripting via SVG Uploadwebedition · webedition cms · CWE-79 | Средняя5,1 | — | 0,3 % | 15 дек. 2025 г. |
- CVE-2014-230240В плане
The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection att
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %webedition · webedition cms19 июл. 2018 г.
- CVE-2023-5388334Наблюдать
Webedition CMS v2.9.8.8 Remote Code Execution via PHP Page Creation
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %webedition · webedition cms15 дек. 2025 г.
- CVE-2014-230331Наблюдать
Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %webedition · webedition cms13 июн. 2014 г.
- CVE-2024-2841826Наблюдать
Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php
СредняяCVSS 6,5Эксплойта нетEPSS 0 %webedition · webedition cms14 мар. 2024 г.
- CVE-2024-2841725Наблюдать
Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.
СредняяCVSS 6,3Эксплойта нетEPSS 0 %webedition · webedition cms14 мар. 2024 г.
- CVE-2014-525822Наблюдать
Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitr
СредняяCVSS 4,0Proof of conceptEPSS 20 %webedition · webedition cms6 нояб. 2014 г.
- CVE-2009-122221Наблюдать
Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and magic_quotes_gpc is d
СредняяCVSS 5,1Proof of conceptEPSS 2 %webedition · webedition2 апр. 2009 г.
- CVE-2023-5388420Наблюдать
Webedition CMS v2.9.8.8 Stored Cross-Site Scripting via SVG Upload
СредняяCVSS 5,1Эксплойта нетEPSS 0 %webedition · webedition cms15 дек. 2025 г.