elefantcms records
14 published records for vendor elefantcms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 92.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-269 Improper Privilege Management1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-16975No exploit | An issue was discovered in Elefant CMS before 2.0.7.elefantcms · elefant · CWE-94 | Critical9.8 | — | 3.7% | Sep 12, 2018 |
40Plan | CVE-2018-16974No exploit | An issue was discovered in Elefant CMS before 2.0.7.elefantcms · elefant · CWE-434 | Critical9.8 | — | 3.6% | Sep 12, 2018 |
39Monitor | CVE-2018-15601No exploit | apps/filemanager/handlers/upload/drop.php in Elefant CMS 2.0.3 performs a urldecode step too late in the "Cannot upload executable files" prelefantcms · elefantcms · CWE-20 | Critical9.8 | — | 1.6% | Aug 20, 2018 |
35Monitor | CVE-2017-20064No exploit | Elefant CMS layout code injectionelefantcms · elefant cms · CWE-94 | High8.8 | — | 1.1% | Jun 20, 2022 |
35Monitor | CVE-2017-20063No exploit | Elefant CMS File Upload drop privileges managementelefantcms · elefant cms · CWE-269 | High8.8 | — | 0.9% | Jun 20, 2022 |
35Monitor | CVE-2018-16387No exploit | An issue was discovered in Elefant CMS before 2.0.5.elefantcms · elefantcms · CWE-352 | High8.8 | — | 0.7% | Sep 2, 2018 |
35Monitor | CVE-2017-20062No exploit | Elefant CMS cross-site request forgeryelefantcms · elefant cms · CWE-352 | High8.8 | — | 0.4% | Jun 20, 2022 |
24Monitor | CVE-2017-20058No exploit | Elefant CMS Version Comparison Persistent cross site scritingelefantcms · elefantcms · CWE-80 | Medium6.1 | — | 0.8% | Jun 20, 2022 |
24Monitor | CVE-2017-20057No exploit | Elefant CMS Persistent cross site scritingelefantcms · elefant cms · CWE-80 | Medium6.1 | — | 0.6% | Jun 20, 2022 |
21Monitor | CVE-2017-20059No exploit | Elefant CMS Title Persistent cross site scritingelefantcms · elefant cms · CWE-80 | Medium5.4 | — | 0.5% | Jun 20, 2022 |
21Monitor | CVE-2017-20060No exploit | Elefant CMS Blog Post Persistent cross site scritingelefantcms · elefant cms · CWE-80 | Medium5.4 | — | 0.5% | Jun 20, 2022 |
21Monitor | CVE-2017-20061No exploit | Elefant CMS extended Reflected cross site scritingelefantcms · elefant cms · CWE-80 | Medium5.4 | — | 0.5% | Jun 20, 2022 |
17Monitor | CVE-2012-1296No exploit | Multiple cross-site scripting (XSS) vulnerabilities in apps/admin/handlers/preview.php in Elefant CMS 1.0.x before 1.0.2-Beta and 1.1.x befoelefantcms · elefantcms · CWE-79 | Medium4.3 | — | 1.3% | Aug 26, 2012 |
17Monitor | CVE-2012-6521No exploit | Cross-site scripting (XSS) vulnerability in apps/admin/handlers/versions.php in Elefant CMS 1.2.0 allows remote attackers to inject arbitrarelefantcms · elefantcms · CWE-79 | Medium4.3 | — | 1.0% | Jan 23, 2013 |
- CVE-2018-1697540Plan
An issue was discovered in Elefant CMS before 2.0.7.
CriticalCVSS 9.8No exploitEPSS 4%elefantcms · elefantSep 12, 2018
- CVE-2018-1697440Plan
An issue was discovered in Elefant CMS before 2.0.7.
CriticalCVSS 9.8No exploitEPSS 4%elefantcms · elefantSep 12, 2018
- CVE-2018-1560139Monitor
apps/filemanager/handlers/upload/drop.php in Elefant CMS 2.0.3 performs a urldecode step too late in the "Cannot upload executable files" pr
CriticalCVSS 9.8No exploitEPSS 2%elefantcms · elefantcmsAug 20, 2018
- CVE-2017-2006435Monitor
Elefant CMS layout code injection
HighCVSS 8.8No exploitEPSS 1%elefantcms · elefant cmsJun 20, 2022
- CVE-2017-2006335Monitor
Elefant CMS File Upload drop privileges management
HighCVSS 8.8No exploitEPSS 1%elefantcms · elefant cmsJun 20, 2022
- CVE-2018-1638735Monitor
An issue was discovered in Elefant CMS before 2.0.5.
HighCVSS 8.8No exploitEPSS 1%elefantcms · elefantcmsSep 2, 2018
- CVE-2017-2006235Monitor
Elefant CMS cross-site request forgery
HighCVSS 8.8No exploitEPSS 0%elefantcms · elefant cmsJun 20, 2022
- CVE-2017-2005824Monitor
Elefant CMS Version Comparison Persistent cross site scriting
MediumCVSS 6.1No exploitEPSS 1%elefantcms · elefantcmsJun 20, 2022
- CVE-2017-2005724Monitor
Elefant CMS Persistent cross site scriting
MediumCVSS 6.1No exploitEPSS 1%elefantcms · elefant cmsJun 20, 2022
- CVE-2017-2005921Monitor
Elefant CMS Title Persistent cross site scriting
MediumCVSS 5.4No exploitEPSS 1%elefantcms · elefant cmsJun 20, 2022
- CVE-2017-2006021Monitor
Elefant CMS Blog Post Persistent cross site scriting
MediumCVSS 5.4No exploitEPSS 1%elefantcms · elefant cmsJun 20, 2022
- CVE-2017-2006121Monitor
Elefant CMS extended Reflected cross site scriting
MediumCVSS 5.4No exploitEPSS 0%elefantcms · elefant cmsJun 20, 2022
- CVE-2012-129617Monitor
Multiple cross-site scripting (XSS) vulnerabilities in apps/admin/handlers/preview.php in Elefant CMS 1.0.x before 1.0.2-Beta and 1.1.x befo
MediumCVSS 4.3No exploitEPSS 1%elefantcms · elefantcmsAug 26, 2012
- CVE-2012-652117Monitor
Cross-site scripting (XSS) vulnerability in apps/admin/handlers/versions.php in Elefant CMS 1.2.0 allows remote attackers to inject arbitrar
MediumCVSS 4.3No exploitEPSS 1%elefantcms · elefantcmsJan 23, 2013