Skip to content
Noroxi

batflat records

5 published records for vendor batflat.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 21
  2. 22

Bar: total · dark part: CISA KEV.

Attack profile

All records

5 records
  • Sruu.pl in Batflat 1.3.6 allows an authenticated user to perform code injection (and consequently Remote Code Execution) via the input field

    HighCVSS 7.2No exploitEPSS 7%

    batflat · batflatFeb 15, 2021

  • Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.

    HighCVSS 7.5No exploitEPSS 1%

    batflat · batflatMar 1, 2022

  • Cross-site scripting (XSS) vulnerability in Galleries in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML vi

    MediumCVSS 5.4No exploitEPSS 1%

    batflat · batflatMar 11, 2021

  • Cross-site scripting (XSS) vulnerability in Snippets in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML via

    MediumCVSS 5.4No exploitEPSS 1%

    batflat · batflatMar 11, 2021

  • Cross-site scripting (XSS) vulnerability in Navigation in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary web script or HTML v

    MediumCVSS 5.4No exploitEPSS 1%

    batflat · batflatMar 11, 2021