Skip to content
Noroxi

chronoengine records

5 published records for vendor chronoengine.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

5 records
  • Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for Joomla! allow remote

    HighCVSS 7.5Proof of conceptEPSS 34%

    chronoengine · chronoformsFeb 4, 2008

  • WordPress Chronoforms Plugin <= 7.0.9 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    chronoengine · chronoformsMay 25, 2023

  • ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.

    MediumCVSS 5.3Proof of conceptEPSS 8%

    chronoengine · chronoforumsJan 12, 2022

  • Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post.

    MediumCVSS 6.1No exploitEPSS 1%

    chronoengine · chronoforumsNov 16, 2020

  • ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files.

    LowCVSS 2.7No exploitEPSS 1%

    chronoengine · chronoforumsJan 12, 2022