dotnetfoundation records
9 published records for vendor dotnetfoundation.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 33.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-400 Uncontrolled Resource Consumption1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2021-25976No exploit | Piranha CMS - Site-wide Cross-Site Request Forgery (CSRF)dotnetfoundation · piranha cms · CWE-352 | High8.1 | — | 0.5% | Nov 16, 2021 |
30Monitor | CVE-2022-4952No exploit | OmniSharp csharp-language-server-protocol JSON Serializer SerializerBase.cs CreateSerializerSettings resource consumptiondotnetfoundation · c\# language server protocol · CWE-400 | High7.5 | — | 0.9% | Jul 16, 2023 |
27Monitor | CVE-2025-57692No exploit | PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, enabling execution ofdotnetfoundation · piranha cms · CWE-79 | Medium6.8 | — | 0.3% | Sep 26, 2025 |
24Monitor | CVE-2025-61413No exploit | A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers to execute arbitrarydotnetfoundation · piranha cms · CWE-79 | Medium6.1 | — | 0.3% | Oct 23, 2025 |
24Monitor | CVE-2025-67291No exploit | A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scriptsdotnetfoundation · piranha cms · CWE-79 | Medium6.1 | — | 0.2% | Dec 22, 2025 |
24Monitor | CVE-2025-67290No exploit | A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to execute arbitrary webdotnetfoundation · piranha cms · CWE-79 | Medium6.1 | — | 0.2% | Dec 22, 2025 |
21Monitor | CVE-2021-25977No exploit | Piranha CMS - Stored XSS in Page Titledotnetfoundation · piranha cms · CWE-79 | Medium5.4 | — | 0.7% | Oct 25, 2021 |
18Monitor | CVE-2024-55342No exploit | A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /manager/media.dotnetfoundation · piranha cms · CWE-79 | Medium4.7 | — | 0.5% | Dec 20, 2024 |
18Monitor | CVE-2024-55341No exploit | A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaScript in the web brodotnetfoundation · piranha cms · CWE-79 | Medium4.7 | — | 0.5% | Dec 20, 2024 |
- CVE-2021-2597632Monitor
Piranha CMS - Site-wide Cross-Site Request Forgery (CSRF)
HighCVSS 8.1No exploitEPSS 0%dotnetfoundation · piranha cmsNov 16, 2021
- CVE-2022-495230Monitor
OmniSharp csharp-language-server-protocol JSON Serializer SerializerBase.cs CreateSerializerSettings resource consumption
HighCVSS 7.5No exploitEPSS 1%dotnetfoundation · c\# language server protocolJul 16, 2023
- CVE-2025-5769227Monitor
PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, enabling execution of
MediumCVSS 6.8No exploitEPSS 0%dotnetfoundation · piranha cmsSep 26, 2025
- CVE-2025-6141324Monitor
A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers to execute arbitrary
MediumCVSS 6.1No exploitEPSS 0%dotnetfoundation · piranha cmsOct 23, 2025
- CVE-2025-6729124Monitor
A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts
MediumCVSS 6.1No exploitEPSS 0%dotnetfoundation · piranha cmsDec 22, 2025
- CVE-2025-6729024Monitor
A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to execute arbitrary web
MediumCVSS 6.1No exploitEPSS 0%dotnetfoundation · piranha cmsDec 22, 2025
- CVE-2021-2597721Monitor
Piranha CMS - Stored XSS in Page Title
MediumCVSS 5.4No exploitEPSS 1%dotnetfoundation · piranha cmsOct 25, 2021
- CVE-2024-5534218Monitor
A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /manager/media.
MediumCVSS 4.7No exploitEPSS 1%dotnetfoundation · piranha cmsDec 20, 2024
- CVE-2024-5534118Monitor
A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaScript in the web bro
MediumCVSS 4.7No exploitEPSS 0%dotnetfoundation · piranha cmsDec 20, 2024