pivotx records
16 published records for vendor pivotx.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 6.3%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-20 Improper Input Validation1
- CWE-255 Credentials Management Errors1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2017-7570No exploit | PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (spivotx · pivotx · CWE-94 | High8.8 | — | 1.5% | Apr 7, 2017 |
35Monitor | CVE-2017-8402No exploit | PivotX 2.3.11 allows remote authenticated users to execute arbitrary PHP code via vectors involving an upload of a .htaccess file.pivotx · pivotx · CWE-94 | High8.8 | — | 1.3% | May 31, 2017 |
31Monitor | CVE-2015-5457No exploit | PivotX before 2.3.11 does not validate the new file extension when renaming a file with multiple extensions, which allows remote attackers tpivotx · pivotx · CWE-20 | High7.5 | — | 4.7% | Jul 8, 2015 |
31Monitor | CVE-2011-1035No exploit | The password reset in PivotX before 2.2.4 allows remote attackers to modify the passwords of arbitrary users via unspecified vectors.pivotx · pivotx · CWE-255 | High7.5 | — | 4.0% | Feb 18, 2011 |
31Monitor | CVE-2014-0342No exploit | Multiple unrestricted file upload vulnerabilities in fileupload.php in PivotX before 2.3.9 allow remote authenticated users to execute arbitpivotx · pivotx | High7.5 | — | 2.1% | Apr 15, 2014 |
28Monitor | CVE-2015-5458No exploit | Session fixation vulnerability in fileupload.php in PivotX before 2.3.11 allows remote attackers to hijack web sessions via the sess parametpivotx · pivotx | Medium6.8 | — | 2.5% | Jul 8, 2015 |
28Monitor | CVE-2017-14958No exploit | lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via pivotx · pivotx · CWE-434 | High7.2 | — | 1.3% | Oct 1, 2017 |
24Monitor | CVE-2017-9332No exploit | The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the pivotx · pivotx · CWE-79 | Medium6.1 | — | 0.6% | Jun 6, 2017 |
22Monitor | CVE-2025-52367Weaponized | Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the subtitle field.pivotx · pivotx · CWE-79 | Medium5.4 | — | 4.1% | Sep 22, 2025 |
20Monitor | CVE-2011-0774No exploit | PivotX before 2.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) includes/ping.php and (2) includes/spivotx · pivotx · CWE-200 | Medium5.0 | — | 1.4% | Feb 3, 2011 |
20Monitor | CVE-2011-0775No exploit | pivotx/modules/module_image.php in PivotX 2.2.2 allows remote attackers to obtain sensitive information via a non-existent file in the imagepivotx · pivotx · CWE-200 | Medium5.0 | — | 1.2% | Feb 3, 2011 |
18Monitor | CVE-2012-2274Proof of concept | Cross-site scripting (XSS) vulnerability in pivotx/ajaxhelper.php in PivotX 2.3.2 and earlier allows remote attackers to inject arbitrary wepivotx · pivotx · CWE-79 | Medium4.3 | — | 3.3% | Aug 13, 2012 |
18Monitor | CVE-2011-0772Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow remote attackers to injpivotx · pivotx · CWE-79 | Medium4.3 | — | 2.5% | Feb 3, 2011 |
18Monitor | CVE-2011-0773Proof of concept | Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attackers to inject arbitrapivotx · pivotx · CWE-79 | Medium4.3 | — | 2.4% | Feb 3, 2011 |
18Monitor | CVE-2015-5456No exploit | Cross-site scripting (XSS) vulnerability in the form method in modules/formclass.php in PivotX before 2.3.11 allows remote attackers to injepivotx · pivotx · CWE-79 | Medium4.3 | — | 2.1% | Jul 8, 2015 |
15Monitor | CVE-2014-0341No exploit | Multiple cross-site scripting (XSS) vulnerabilities in PivotX before 2.3.9 allow remote authenticated users to inject arbitrary web script opivotx · pivotx · CWE-79 | Low3.5 | — | 1.9% | Apr 15, 2014 |
- CVE-2017-757035Monitor
PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (s
HighCVSS 8.8No exploitEPSS 1%pivotx · pivotxApr 7, 2017
- CVE-2017-840235Monitor
PivotX 2.3.11 allows remote authenticated users to execute arbitrary PHP code via vectors involving an upload of a .htaccess file.
HighCVSS 8.8No exploitEPSS 1%pivotx · pivotxMay 31, 2017
- CVE-2015-545731Monitor
PivotX before 2.3.11 does not validate the new file extension when renaming a file with multiple extensions, which allows remote attackers t
HighCVSS 7.5No exploitEPSS 5%pivotx · pivotxJul 8, 2015
- CVE-2011-103531Monitor
The password reset in PivotX before 2.2.4 allows remote attackers to modify the passwords of arbitrary users via unspecified vectors.
HighCVSS 7.5No exploitEPSS 4%pivotx · pivotxFeb 18, 2011
- CVE-2014-034231Monitor
Multiple unrestricted file upload vulnerabilities in fileupload.php in PivotX before 2.3.9 allow remote authenticated users to execute arbit
HighCVSS 7.5No exploitEPSS 2%pivotx · pivotxApr 15, 2014
- CVE-2015-545828Monitor
Session fixation vulnerability in fileupload.php in PivotX before 2.3.11 allows remote attackers to hijack web sessions via the sess paramet
MediumCVSS 6.8No exploitEPSS 2%pivotx · pivotxJul 8, 2015
- CVE-2017-1495828Monitor
lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via
HighCVSS 7.2No exploitEPSS 1%pivotx · pivotxOct 1, 2017
- CVE-2017-933224Monitor
The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the
MediumCVSS 6.1No exploitEPSS 1%pivotx · pivotxJun 6, 2017
- CVE-2025-5236722Monitor
Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the subtitle field.
MediumCVSS 5.4WeaponizedEPSS 4%pivotx · pivotxSep 22, 2025
- CVE-2011-077420Monitor
PivotX before 2.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) includes/ping.php and (2) includes/s
MediumCVSS 5.0No exploitEPSS 1%pivotx · pivotxFeb 3, 2011
- CVE-2011-077520Monitor
pivotx/modules/module_image.php in PivotX 2.2.2 allows remote attackers to obtain sensitive information via a non-existent file in the image
MediumCVSS 5.0No exploitEPSS 1%pivotx · pivotxFeb 3, 2011
- CVE-2012-227418Monitor
Cross-site scripting (XSS) vulnerability in pivotx/ajaxhelper.php in PivotX 2.3.2 and earlier allows remote attackers to inject arbitrary we
MediumCVSS 4.3Proof of conceptEPSS 3%pivotx · pivotxAug 13, 2012
- CVE-2011-077218Monitor
Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow remote attackers to inj
MediumCVSS 4.3Proof of conceptEPSS 3%pivotx · pivotxFeb 3, 2011
- CVE-2011-077318Monitor
Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attackers to inject arbitra
MediumCVSS 4.3Proof of conceptEPSS 2%pivotx · pivotxFeb 3, 2011
- CVE-2015-545618Monitor
Cross-site scripting (XSS) vulnerability in the form method in modules/formclass.php in PivotX before 2.3.11 allows remote attackers to inje
MediumCVSS 4.3No exploitEPSS 2%pivotx · pivotxJul 8, 2015
- CVE-2014-034115Monitor
Multiple cross-site scripting (XSS) vulnerabilities in PivotX before 2.3.9 allow remote authenticated users to inject arbitrary web script o
LowCVSS 3.5No exploitEPSS 2%pivotx · pivotxApr 15, 2014