ShowDoc records
41 published records for vendor showdoc.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 80.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')16
- CWE-434 Unrestricted Upload of File with Dangerous Type9
- CWE-352 Cross-Site Request Forgery (CSRF)7
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)2
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
41 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-36440No exploit | Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component Ashowdoc · showdoc · CWE-434 | Critical9.8 | — | 4.8% | Sep 8, 2021 |
39Monitor | CVE-2022-0362No exploit | SQL Injection in star7th/showdocshowdoc · showdoc · CWE-89 | Critical9.8 | — | 1.5% | Jan 26, 2022 |
39Monitor | CVE-2021-41745No exploit | ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.showdoc · showdoc · CWE-434 | Critical9.8 | — | 1.4% | Oct 22, 2021 |
35Monitor | CVE-2021-4017No exploit | Cross-Site Request Forgery (CSRF) in star7th/showdocshowdoc · showdoc · CWE-352 | High8.8 | — | 0.6% | Dec 1, 2021 |
35Monitor | CVE-2021-4168No exploit | Cross-Site Request Forgery (CSRF) in star7th/showdocshowdoc · showdoc · CWE-352 | High8.8 | — | 0.6% | Dec 26, 2021 |
31Monitor | CVE-2022-0409No exploit | Unrestricted Upload of File with Dangerous Type in star7th/showdocshowdoc · showdoc · CWE-434 | High7.8 | — | 0.9% | Feb 19, 2022 |
28Monitor | CVE-2022-1034No exploit | There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in star7th/showdocshowdoc · showdoc · CWE-434 | High7.2 | — | 1.5% | Mar 22, 2022 |
26Monitor | CVE-2018-19609No exploit | ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading noteshowdoc · showdoc · CWE-200 | Medium6.5 | — | 1.2% | Nov 27, 2018 |
26Monitor | CVE-2021-3990No exploit | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in star7th/showdocshowdoc · showdoc · CWE-338 | Medium6.5 | — | 0.9% | Dec 1, 2021 |
26Monitor | CVE-2021-3993No exploit | Cross-Site Request Forgery (CSRF) in star7th/showdocshowdoc · showdoc · CWE-352 | Medium6.5 | — | 0.5% | Dec 1, 2021 |
26Monitor | CVE-2018-19621No exploit | server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.showdoc · showdoc · CWE-352 | Medium6.5 | — | 0.4% | Nov 28, 2018 |
26Monitor | CVE-2021-3683No exploit | Cross-Site Request Forgery (CSRF) in star7th/showdocshowdoc · showdoc · CWE-352 | Medium6.5 | — | 0.4% | Nov 13, 2021 |
24Monitor | CVE-2022-0951No exploit | File Upload Restriction Bypass leading to Stored XSS Vulnerability in star7th/showdocshowdoc · showdoc · CWE-434 | Medium6.1 | — | 0.9% | Mar 15, 2022 |
24Monitor | CVE-2018-19433No exploit | ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.showdoc · showdoc · CWE-79 | Medium6.1 | — | 0.9% | Nov 22, 2018 |
24Monitor | CVE-2021-4000No exploit | Open Redirect in star7th/showdocshowdoc · showdoc · CWE-601 | Medium6.1 | — | 0.8% | Dec 3, 2021 |
24Monitor | CVE-2021-3989No exploit | Open Redirect in star7th/showdocshowdoc · showdoc · CWE-601 | Medium6.1 | — | 0.8% | Dec 1, 2021 |
23Monitor | CVE-2021-3678No exploit | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in star7th/showdocshowdoc · showdoc · CWE-338 | Medium5.9 | — | 1.1% | Aug 4, 2021 |
22Monitor | CVE-2022-0967Proof of concept | Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in star7th/showdocshowdoc · showdoc · CWE-79 | Medium5.4 | — | 3.3% | Mar 15, 2022 |
21Monitor | CVE-2022-0079No exploit | Generation of Error Message Containing Sensitive Information in star7th/showdocshowdoc · showdoc · CWE-209 | Medium5.3 | — | 1.0% | Jan 2, 2022 |
21Monitor | CVE-2022-0962No exploit | Stored XSS viva .webma file upload in star7th/showdocshowdoc · showdoc · CWE-434 | Medium5.4 | — | 0.9% | Mar 14, 2022 |
21Monitor | CVE-2022-0965No exploit | Stored XSS viva .ofd file upload in star7th/showdocshowdoc · showdoc · CWE-79 | Medium5.4 | — | 0.9% | Mar 15, 2022 |
21Monitor | CVE-2022-0960No exploit | Stored XSS viva .properties file upload in star7th/showdocshowdoc · showdoc · CWE-434 | Medium5.4 | — | 0.9% | Mar 14, 2022 |
21Monitor | CVE-2022-0964No exploit | Stored XSS viva .webmv file upload in star7th/showdocshowdoc · showdoc · CWE-79 | Medium5.4 | — | 0.8% | Mar 15, 2022 |
21Monitor | CVE-2022-0946No exploit | Stored XSS viva cshtm file upload in star7th/showdocshowdoc · showdoc · CWE-79 | Medium5.4 | — | 0.8% | Mar 14, 2022 |
21Monitor | CVE-2022-0945No exploit | Stored XSS viva axd and cshtml file upload in star7th/showdoc in star7th/showdocshowdoc · showdoc · CWE-434 | Medium5.4 | — | 0.8% | Mar 15, 2022 |
- CVE-2021-3644040Plan
Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component A
CriticalCVSS 9.8No exploitEPSS 5%showdoc · showdocSep 8, 2021
- CVE-2022-036239Monitor
SQL Injection in star7th/showdoc
CriticalCVSS 9.8No exploitEPSS 1%showdoc · showdocJan 26, 2022
- CVE-2021-4174539Monitor
ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.
CriticalCVSS 9.8No exploitEPSS 1%showdoc · showdocOct 22, 2021
- CVE-2021-401735Monitor
Cross-Site Request Forgery (CSRF) in star7th/showdoc
HighCVSS 8.8No exploitEPSS 1%showdoc · showdocDec 1, 2021
- CVE-2021-416835Monitor
Cross-Site Request Forgery (CSRF) in star7th/showdoc
HighCVSS 8.8No exploitEPSS 1%showdoc · showdocDec 26, 2021
- CVE-2022-040931Monitor
Unrestricted Upload of File with Dangerous Type in star7th/showdoc
HighCVSS 7.8No exploitEPSS 1%showdoc · showdocFeb 19, 2022
- CVE-2022-103428Monitor
There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in star7th/showdoc
HighCVSS 7.2No exploitEPSS 1%showdoc · showdocMar 22, 2022
- CVE-2018-1960926Monitor
ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note
MediumCVSS 6.5No exploitEPSS 1%showdoc · showdocNov 27, 2018
- CVE-2021-399026Monitor
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in star7th/showdoc
MediumCVSS 6.5No exploitEPSS 1%showdoc · showdocDec 1, 2021
- CVE-2021-399326Monitor
Cross-Site Request Forgery (CSRF) in star7th/showdoc
MediumCVSS 6.5No exploitEPSS 1%showdoc · showdocDec 1, 2021
- CVE-2018-1962126Monitor
server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.
MediumCVSS 6.5No exploitEPSS 0%showdoc · showdocNov 28, 2018
- CVE-2021-368326Monitor
Cross-Site Request Forgery (CSRF) in star7th/showdoc
MediumCVSS 6.5No exploitEPSS 0%showdoc · showdocNov 13, 2021
- CVE-2022-095124Monitor
File Upload Restriction Bypass leading to Stored XSS Vulnerability in star7th/showdoc
MediumCVSS 6.1No exploitEPSS 1%showdoc · showdocMar 15, 2022
- CVE-2018-1943324Monitor
ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.
MediumCVSS 6.1No exploitEPSS 1%showdoc · showdocNov 22, 2018
- CVE-2021-400024Monitor
Open Redirect in star7th/showdoc
MediumCVSS 6.1No exploitEPSS 1%showdoc · showdocDec 3, 2021
- CVE-2021-398924Monitor
Open Redirect in star7th/showdoc
MediumCVSS 6.1No exploitEPSS 1%showdoc · showdocDec 1, 2021
- CVE-2021-367823Monitor
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in star7th/showdoc
MediumCVSS 5.9No exploitEPSS 1%showdoc · showdocAug 4, 2021
- CVE-2022-096722Monitor
Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in star7th/showdoc
MediumCVSS 5.4Proof of conceptEPSS 3%showdoc · showdocMar 15, 2022
- CVE-2022-007921Monitor
Generation of Error Message Containing Sensitive Information in star7th/showdoc
MediumCVSS 5.3No exploitEPSS 1%showdoc · showdocJan 2, 2022
- CVE-2022-096221Monitor
Stored XSS viva .webma file upload in star7th/showdoc
MediumCVSS 5.4No exploitEPSS 1%showdoc · showdocMar 14, 2022
- CVE-2022-096521Monitor
Stored XSS viva .ofd file upload in star7th/showdoc
MediumCVSS 5.4No exploitEPSS 1%showdoc · showdocMar 15, 2022
- CVE-2022-096021Monitor
Stored XSS viva .properties file upload in star7th/showdoc
MediumCVSS 5.4No exploitEPSS 1%showdoc · showdocMar 14, 2022
- CVE-2022-096421Monitor
Stored XSS viva .webmv file upload in star7th/showdoc
MediumCVSS 5.4No exploitEPSS 1%showdoc · showdocMar 15, 2022
- CVE-2022-094621Monitor
Stored XSS viva cshtm file upload in star7th/showdoc
MediumCVSS 5.4No exploitEPSS 1%showdoc · showdocMar 14, 2022
- CVE-2022-094521Monitor
Stored XSS viva axd and cshtml file upload in star7th/showdoc in star7th/showdoc
MediumCVSS 5.4No exploitEPSS 1%showdoc · showdocMar 15, 2022