Skip to content
Noroxi

ShowDoc records

41 published records for vendor showdoc.

All records

41 records
  • Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component A

    CriticalCVSS 9.8No exploitEPSS 5%

    showdoc · showdocSep 8, 2021

  • CVE-2022-0362
    39Monitor

    SQL Injection in star7th/showdoc

    CriticalCVSS 9.8No exploitEPSS 1%

    showdoc · showdocJan 26, 2022

  • ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.

    CriticalCVSS 9.8No exploitEPSS 1%

    showdoc · showdocOct 22, 2021

  • CVE-2021-4017
    35Monitor

    Cross-Site Request Forgery (CSRF) in star7th/showdoc

    HighCVSS 8.8No exploitEPSS 1%

    showdoc · showdocDec 1, 2021

  • CVE-2021-4168
    35Monitor

    Cross-Site Request Forgery (CSRF) in star7th/showdoc

    HighCVSS 8.8No exploitEPSS 1%

    showdoc · showdocDec 26, 2021

  • CVE-2022-0409
    31Monitor

    Unrestricted Upload of File with Dangerous Type in star7th/showdoc

    HighCVSS 7.8No exploitEPSS 1%

    showdoc · showdocFeb 19, 2022

  • CVE-2022-1034
    28Monitor

    There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in star7th/showdoc

    HighCVSS 7.2No exploitEPSS 1%

    showdoc · showdocMar 22, 2022

  • ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note

    MediumCVSS 6.5No exploitEPSS 1%

    showdoc · showdocNov 27, 2018

  • CVE-2021-3990
    26Monitor

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in star7th/showdoc

    MediumCVSS 6.5No exploitEPSS 1%

    showdoc · showdocDec 1, 2021

  • CVE-2021-3993
    26Monitor

    Cross-Site Request Forgery (CSRF) in star7th/showdoc

    MediumCVSS 6.5No exploitEPSS 1%

    showdoc · showdocDec 1, 2021

  • server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.

    MediumCVSS 6.5No exploitEPSS 0%

    showdoc · showdocNov 28, 2018

  • CVE-2021-3683
    26Monitor

    Cross-Site Request Forgery (CSRF) in star7th/showdoc

    MediumCVSS 6.5No exploitEPSS 0%

    showdoc · showdocNov 13, 2021

  • CVE-2022-0951
    24Monitor

    File Upload Restriction Bypass leading to Stored XSS Vulnerability in star7th/showdoc

    MediumCVSS 6.1No exploitEPSS 1%

    showdoc · showdocMar 15, 2022

  • ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.

    MediumCVSS 6.1No exploitEPSS 1%

    showdoc · showdocNov 22, 2018

  • CVE-2021-4000
    24Monitor

    Open Redirect in star7th/showdoc

    MediumCVSS 6.1No exploitEPSS 1%

    showdoc · showdocDec 3, 2021

  • CVE-2021-3989
    24Monitor

    Open Redirect in star7th/showdoc

    MediumCVSS 6.1No exploitEPSS 1%

    showdoc · showdocDec 1, 2021

  • CVE-2021-3678
    23Monitor

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in star7th/showdoc

    MediumCVSS 5.9No exploitEPSS 1%

    showdoc · showdocAug 4, 2021

  • CVE-2022-0967
    22Monitor

    Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in star7th/showdoc

    MediumCVSS 5.4Proof of conceptEPSS 3%

    showdoc · showdocMar 15, 2022

  • CVE-2022-0079
    21Monitor

    Generation of Error Message Containing Sensitive Information in star7th/showdoc

    MediumCVSS 5.3No exploitEPSS 1%

    showdoc · showdocJan 2, 2022

  • CVE-2022-0962
    21Monitor

    Stored XSS viva .webma file upload in star7th/showdoc

    MediumCVSS 5.4No exploitEPSS 1%

    showdoc · showdocMar 14, 2022

  • CVE-2022-0965
    21Monitor

    Stored XSS viva .ofd file upload in star7th/showdoc

    MediumCVSS 5.4No exploitEPSS 1%

    showdoc · showdocMar 15, 2022

  • CVE-2022-0960
    21Monitor

    Stored XSS viva .properties file upload in star7th/showdoc

    MediumCVSS 5.4No exploitEPSS 1%

    showdoc · showdocMar 14, 2022

  • CVE-2022-0964
    21Monitor

    Stored XSS viva .webmv file upload in star7th/showdoc

    MediumCVSS 5.4No exploitEPSS 1%

    showdoc · showdocMar 15, 2022

  • CVE-2022-0946
    21Monitor

    Stored XSS viva cshtm file upload in star7th/showdoc

    MediumCVSS 5.4No exploitEPSS 1%

    showdoc · showdocMar 14, 2022

  • CVE-2022-0945
    21Monitor

    Stored XSS viva axd and cshtml file upload in star7th/showdoc in star7th/showdoc

    MediumCVSS 5.4No exploitEPSS 1%

    showdoc · showdocMar 15, 2022