chronoengine records
5 published records for vendor chronoengine.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2008-0567Proof of concept | Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for Joomla! allow remote chronoengine · chronoforms · CWE-94 | High7.5 | — | 34.3% | Feb 4, 2008 |
35Monitor | CVE-2022-47135No exploit | WordPress Chronoforms Plugin <= 7.0.9 is vulnerable to Cross Site Request Forgery (CSRF)chronoengine · chronoforms · CWE-352 | High8.8 | — | 0.3% | May 25, 2023 |
24Monitor | CVE-2021-28377Proof of concept | ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.chronoengine · chronoforums · CWE-22 | Medium5.3 | — | 8.4% | Jan 12, 2022 |
24Monitor | CVE-2020-27459No exploit | Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post.chronoengine · chronoforums · CWE-79 | Medium6.1 | — | 0.9% | Nov 16, 2020 |
10Monitor | CVE-2021-28376No exploit | ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files.chronoengine · chronoforums · CWE-22 | Low2.7 | — | 1.1% | Jan 12, 2022 |
- CVE-2008-056740Plan
Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for Joomla! allow remote
HighCVSS 7.5Proof of conceptEPSS 34%chronoengine · chronoformsFeb 4, 2008
- CVE-2022-4713535Monitor
WordPress Chronoforms Plugin <= 7.0.9 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%chronoengine · chronoformsMay 25, 2023
- CVE-2021-2837724Monitor
ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.
MediumCVSS 5.3Proof of conceptEPSS 8%chronoengine · chronoforumsJan 12, 2022
- CVE-2020-2745924Monitor
Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post.
MediumCVSS 6.1No exploitEPSS 1%chronoengine · chronoforumsNov 16, 2020
- CVE-2021-2837610Monitor
ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files.
LowCVSS 2.7No exploitEPSS 1%chronoengine · chronoforumsJan 12, 2022