Pagekit records
13 published records for vendor pagekit.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 15.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2022-38916No exploit | A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious filespagekit · pagekit · CWE-434 | Critical9.8 | — | 17.9% | Sep 20, 2022 |
39Monitor | CVE-2021-44135No exploit | pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.pagekit · pagekit · CWE-89 | Critical9.8 | — | 1.5% | Apr 1, 2022 |
39Monitor | CVE-2025-67164No exploit | An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arpagekit · pagekit · CWE-78 | Critical9.9 | — | 0.5% | Dec 17, 2025 |
39Monitor | CVE-2025-67165No exploit | An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.pagekit · pagekit · CWE-639 | Critical9.8 | — | 0.5% | Dec 17, 2025 |
35Monitor | CVE-2019-19013No exploit | A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.pagekit · pagekit · CWE-352 | High8.8 | — | 0.8% | Nov 22, 2019 |
32Monitor | CVE-2017-5594Proof of concept | An issue was discovered in Pagekit CMS before 1.0.11.pagekit · pagekit · CWE-640 | High7.5 | — | 7.0% | Jan 25, 2017 |
31Monitor | CVE-2023-41005No exploit | An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in Upagekit · pagekit · CWE-94 | High7.8 | — | 0.6% | Aug 28, 2023 |
24Monitor | CVE-2018-14381No exploit | Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.pagekit · pagekit · CWE-601 | Medium6.1 | — | 1.0% | Jul 18, 2018 |
24Monitor | CVE-2022-36573No exploit | A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted papagekit · pagekit · CWE-79 | Medium6.1 | — | 0.6% | Aug 28, 2022 |
21Monitor | CVE-2019-16669No exploit | The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is epagekit · pagekit · CWE-203 | Medium5.3 | — | 1.1% | Sep 21, 2019 |
21Monitor | CVE-2021-32245No exploit | In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS.pagekit · pagekit · CWE-79 | Medium5.4 | — | 0.5% | Jun 16, 2021 |
20Monitor | CVE-2018-11564Proof of concept | Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.pagekit · pagekit · CWE-79 | Medium4.8 | — | 3.2% | Jun 1, 2018 |
18Monitor | CVE-2024-45967No exploit | Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.pagekit · pagekit · CWE-79 | Medium4.7 | — | 0.4% | Oct 1, 2024 |
- CVE-2022-3891644Plan
A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files
CriticalCVSS 9.8No exploitEPSS 18%pagekit · pagekitSep 20, 2022
- CVE-2021-4413539Monitor
pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.
CriticalCVSS 9.8No exploitEPSS 2%pagekit · pagekitApr 1, 2022
- CVE-2025-6716439Monitor
An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute ar
CriticalCVSS 9.9No exploitEPSS 1%pagekit · pagekitDec 17, 2025
- CVE-2025-6716539Monitor
An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.
CriticalCVSS 9.8No exploitEPSS 0%pagekit · pagekitDec 17, 2025
- CVE-2019-1901335Monitor
A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.
HighCVSS 8.8No exploitEPSS 1%pagekit · pagekitNov 22, 2019
- CVE-2017-559432Monitor
An issue was discovered in Pagekit CMS before 1.0.11.
HighCVSS 7.5Proof of conceptEPSS 7%pagekit · pagekitJan 25, 2017
- CVE-2023-4100531Monitor
An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in U
HighCVSS 7.8No exploitEPSS 1%pagekit · pagekitAug 28, 2023
- CVE-2018-1438124Monitor
Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.
MediumCVSS 6.1No exploitEPSS 1%pagekit · pagekitJul 18, 2018
- CVE-2022-3657324Monitor
A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted pa
MediumCVSS 6.1No exploitEPSS 1%pagekit · pagekitAug 28, 2022
- CVE-2019-1666921Monitor
The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is e
MediumCVSS 5.3No exploitEPSS 1%pagekit · pagekitSep 21, 2019
- CVE-2021-3224521Monitor
In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS.
MediumCVSS 5.4No exploitEPSS 1%pagekit · pagekitJun 16, 2021
- CVE-2018-1156420Monitor
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.
MediumCVSS 4.8Proof of conceptEPSS 3%pagekit · pagekitJun 1, 2018
- CVE-2024-4596718Monitor
Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.
MediumCVSS 4.7No exploitEPSS 0%pagekit · pagekitOct 1, 2024