Mindskip records
6 published records for vendor mindskip.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-276 Incorrect Default Permissions1
- CWE-346 Origin Validation Error1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-613 Insufficient Session Expiration1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-29401No exploit | xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.mindskip · xzs-mysql · CWE-613 | Critical9.8 | — | 0.8% | Mar 26, 2024 |
30Monitor | CVE-2021-46086No exploit | xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions.mindskip · xzs-mysql · CWE-276 | High7.5 | — | 0.8% | Jan 25, 2022 |
21Monitor | CVE-2022-41431No exploit | xzs v3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /admin/question/edit.mindskip · xzs · CWE-79 | Medium5.4 | — | 0.7% | Oct 17, 2022 |
21Monitor | CVE-2025-1084No exploit | Mindskip xzs-mysql 学之思开源考试系统 cross-site request forgerymindskip · xzs-mysql · CWE-352 | Medium5.3 | — | 0.3% | Feb 6, 2025 |
20Monitor | CVE-2025-1082No exploit | Mindskip xzs-mysql 学之思开源考试系统 Exam Edit edit cross site scriptingmindskip · xzs-mysql · CWE-79 | Medium5.1 | — | 0.4% | Feb 6, 2025 |
9Monitor | CVE-2025-1083No exploit | Mindskip xzs-mysql 学之思开源考试系统 CORS cross-domain policymindskip · xzs-mysql · CWE-346 | Low2.3 | — | 0.3% | Feb 6, 2025 |
- CVE-2024-2940139Monitor
xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.
CriticalCVSS 9.8No exploitEPSS 1%mindskip · xzs-mysqlMar 26, 2024
- CVE-2021-4608630Monitor
xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions.
HighCVSS 7.5No exploitEPSS 1%mindskip · xzs-mysqlJan 25, 2022
- CVE-2022-4143121Monitor
xzs v3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /admin/question/edit.
MediumCVSS 5.4No exploitEPSS 1%mindskip · xzsOct 17, 2022
- CVE-2025-108421Monitor
Mindskip xzs-mysql 学之思开源考试系统 cross-site request forgery
MediumCVSS 5.3No exploitEPSS 0%mindskip · xzs-mysqlFeb 6, 2025
- CVE-2025-108220Monitor
Mindskip xzs-mysql 学之思开源考试系统 Exam Edit edit cross site scripting
MediumCVSS 5.1No exploitEPSS 0%mindskip · xzs-mysqlFeb 6, 2025
- CVE-2025-10839Monitor
Mindskip xzs-mysql 学之思开源考试系统 CORS cross-domain policy
LowCVSS 2.3No exploitEPSS 0%mindskip · xzs-mysqlFeb 6, 2025