Skip to content
Noroxi

creatiwity records

7 published records for vendor creatiwity.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

7 records
  • A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP f

    CriticalCVSS 9.8No exploitEPSS 3%

    creatiwity · witycmsJun 8, 2018

  • CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifyi

    HighCVSS 8.8Proof of conceptEPSS 2%

    creatiwity · witycmsJul 12, 2018

  • An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via a crafted PHP file.

    HighCVSS 8.8No exploitEPSS 1%

    creatiwity · witycmsJun 2, 2022

  • The "utilisateur" menu in Creatiwity wityCMS 0.6.2 modifies the presence of XSS at two input points for user information, with the "first na

    MediumCVSS 5.4No exploitEPSS 1%

    creatiwity · witycmsJun 20, 2019

  • Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creat

    MediumCVSS 4.8Proof of conceptEPSS 2%

    creatiwity · witycmsMay 28, 2018

  • wityCMS 0.6.2 has XSS via the "Site Name" field found in the "Contact" "Configuration" page.

    MediumCVSS 4.8No exploitEPSS 1%

    creatiwity · witycmsSep 10, 2018

  • A "search for user discovery" injection issue exists in Creatiwity wityCMS 0.6.2 via the "Utilisateur" menu.

    MediumCVSS 4.3No exploitEPSS 1%

    creatiwity · witycmsJun 20, 2019