canto records
9 published records for vendor canto.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-918 Server-Side Request Forgery (SSRF)5
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2023-3452Proof of concept | Canto <= 3.0.4 - Unauthenticated Remote File Inclusioncanto · canto · CWE-98 | Critical9.8 | — | 7.0% | Aug 11, 2023 |
39Monitor | CVE-2022-40305No exploit | A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network rescanto · canto · CWE-918 | Critical9.8 | — | 1.5% | Sep 9, 2022 |
39Monitor | CVE-2024-4936No exploit | Canto <= 3.0.8 - Unauthenticated Remote File Inclusioncanto · canto · CWE-98 | Critical9.8 | — | 1.0% | Jun 14, 2024 |
39Monitor | CVE-2024-25096Proof of concept | WordPress canto plugin <= 3.0.7 - Unauth. Remote Code Execution (RCE) vulnerabilitycanto · canto · CWE-94 | Critical9.8 | — | 0.7% | Apr 3, 2024 |
31Monitor | CVE-2013-7416No exploit | canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a canto · canto curses · CWE-77 | High7.5 | — | 2.8% | Dec 3, 2014 |
29Monitor | CVE-2020-28976Proof of concept | The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability.canto · canto · CWE-918 | Medium5.3 | — | 27.8% | Nov 30, 2020 |
28Monitor | CVE-2020-24063No exploit | The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF.canto · canto · CWE-918 | High7.2 | — | 1.5% | Nov 10, 2020 |
26Monitor | CVE-2020-28978Proof of concept | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability.canto · canto · CWE-918 | Medium5.3 | — | 15.4% | Nov 30, 2020 |
26Monitor | CVE-2020-28977Proof of concept | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability.canto · canto · CWE-918 | Medium5.3 | — | 15.4% | Nov 30, 2020 |
- CVE-2023-345241Plan
Canto <= 3.0.4 - Unauthenticated Remote File Inclusion
CriticalCVSS 9.8Proof of conceptEPSS 7%canto · cantoAug 11, 2023
- CVE-2022-4030539Monitor
A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network res
CriticalCVSS 9.8No exploitEPSS 2%canto · cantoSep 9, 2022
- CVE-2024-493639Monitor
Canto <= 3.0.8 - Unauthenticated Remote File Inclusion
CriticalCVSS 9.8No exploitEPSS 1%canto · cantoJun 14, 2024
- CVE-2024-2509639Monitor
WordPress canto plugin <= 3.0.7 - Unauth. Remote Code Execution (RCE) vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 1%canto · cantoApr 3, 2024
- CVE-2013-741631Monitor
canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a
HighCVSS 7.5No exploitEPSS 3%canto · canto cursesDec 3, 2014
- CVE-2020-2897629Monitor
The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability.
MediumCVSS 5.3Proof of conceptEPSS 28%canto · cantoNov 30, 2020
- CVE-2020-2406328Monitor
The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF.
HighCVSS 7.2No exploitEPSS 1%canto · cantoNov 10, 2020
- CVE-2020-2897826Monitor
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability.
MediumCVSS 5.3Proof of conceptEPSS 15%canto · cantoNov 30, 2020
- CVE-2020-2897726Monitor
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability.
MediumCVSS 5.3Proof of conceptEPSS 15%canto · cantoNov 30, 2020