creatiwity records
7 published records for vendor creatiwity.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-20 Improper Input Validation1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-12065No exploit | A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP fcreatiwity · witycms · CWE-20 | Critical9.8 | — | 2.6% | Jun 8, 2018 |
36Monitor | CVE-2018-14029Proof of concept | CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifyicreatiwity · witycms · CWE-352 | High8.8 | — | 2.5% | Jul 12, 2018 |
35Monitor | CVE-2022-29725No exploit | An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via a crafted PHP file.creatiwity · witycms · CWE-434 | High8.8 | — | 1.4% | Jun 2, 2022 |
21Monitor | CVE-2018-16250No exploit | The "utilisateur" menu in Creatiwity wityCMS 0.6.2 modifies the presence of XSS at two input points for user information, with the "first nacreatiwity · witycms · CWE-79 | Medium5.4 | — | 0.6% | Jun 20, 2019 |
20Monitor | CVE-2018-11512Proof of concept | Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatcreatiwity · witycms · CWE-79 | Medium4.8 | — | 2.2% | May 28, 2018 |
19Monitor | CVE-2018-16776No exploit | wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" "Configuration" page.creatiwity · witycms · CWE-79 | Medium4.8 | — | 0.7% | Sep 10, 2018 |
17Monitor | CVE-2018-16251No exploit | A "search for user discovery" injection issue exists in Creatiwity wityCMS 0.6.2 via the "Utilisateur" menu.creatiwity · witycms · CWE-89 | Medium4.3 | — | 0.9% | Jun 20, 2019 |
- CVE-2018-1206540Plan
A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP f
CriticalCVSS 9.8No exploitEPSS 3%creatiwity · witycmsJun 8, 2018
- CVE-2018-1402936Monitor
CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifyi
HighCVSS 8.8Proof of conceptEPSS 2%creatiwity · witycmsJul 12, 2018
- CVE-2022-2972535Monitor
An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via a crafted PHP file.
HighCVSS 8.8No exploitEPSS 1%creatiwity · witycmsJun 2, 2022
- CVE-2018-1625021Monitor
The "utilisateur" menu in Creatiwity wityCMS 0.6.2 modifies the presence of XSS at two input points for user information, with the "first na
MediumCVSS 5.4No exploitEPSS 1%creatiwity · witycmsJun 20, 2019
- CVE-2018-1151220Monitor
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creat
MediumCVSS 4.8Proof of conceptEPSS 2%creatiwity · witycmsMay 28, 2018
- CVE-2018-1677619Monitor
wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" "Configuration" page.
MediumCVSS 4.8No exploitEPSS 1%creatiwity · witycmsSep 10, 2018
- CVE-2018-1625117Monitor
A "search for user discovery" injection issue exists in Creatiwity wityCMS 0.6.2 via the "Utilisateur" menu.
MediumCVSS 4.3No exploitEPSS 1%creatiwity · witycmsJun 20, 2019