x2engine records
15 published records for vendor x2engine.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-20 Improper Input Validation1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2013-5692Proof of concept | Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary lx2engine · x2crm · CWE-22 | High8.5 | — | 5.8% | Sep 30, 2013 |
36Monitor | CVE-2014-2664No exploit | Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/ProfileController.php in x2engine · x2crm · CWE-434 | High8.8 | — | 2.9% | Oct 17, 2017 |
32Monitor | CVE-2015-5074Proof of concept | Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM bex2engine · x2crm · CWE-20 | High7.5 | — | 7.5% | Sep 29, 2015 |
31Monitor | CVE-2014-5297No exploit | The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote attackers to conducx2engine · x2engine · CWE-94 | High7.5 | — | 2.7% | Oct 9, 2014 |
28Monitor | CVE-2015-5075Proof of concept | Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of adminisx2engine · x2crm · CWE-352 | Medium6.8 | — | 2.8% | Sep 29, 2015 |
24Monitor | CVE-2020-21087No exploit | Cross Site Scripting (XSS) in X2Engine X2CRM v6.9 and older allows remote attackers to execute arbitrary code by injecting arbitrary web scrx2engine · x2crm · CWE-79 | Medium6.1 | — | 1.4% | Apr 14, 2021 |
24Monitor | CVE-2021-27288No exploit | Cross Site Scripting (XSS) in X2Engine X2CRM v7.1 allows remote attackers to obtain sensitive information by injecting arbitrary web script x2engine · x2crm · CWE-79 | Medium6.1 | — | 0.9% | Apr 14, 2021 |
22Monitor | CVE-2022-48178Proof of concept | X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action fux2engine · x2crm · CWE-79 | Medium5.4 | — | 1.8% | Apr 14, 2023 |
22Monitor | CVE-2022-48177Proof of concept | X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importMox2engine · x2crm · CWE-79 | Medium5.4 | — | 1.8% | Apr 14, 2023 |
21Monitor | CVE-2014-5298No exploit | FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attackers to bypass the upx2engine · x2engine · CWE-264 | Medium5.0 | — | 3.0% | Oct 9, 2014 |
21Monitor | CVE-2024-48120Proof of concept | X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module.x2engine · x2crm · CWE-79 | Medium5.4 | — | 0.7% | Oct 14, 2024 |
21Monitor | CVE-2021-33853No exploit | A Cross-Site Scripting (XSS) attack can cause arbitrary code (javascript) to run in a user’s browser while the browser is connected to a trux2engine · x2crm · CWE-79 | Medium5.4 | — | 0.6% | Mar 16, 2022 |
19Monitor | CVE-2020-21088No exploit | Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary wx2engine · x2crm · CWE-79 | Medium4.8 | — | 0.8% | Apr 14, 2021 |
18Monitor | CVE-2013-5693Proof of concept | Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via thex2engine · x2crm · CWE-79 | Medium4.3 | — | 3.2% | Sep 30, 2013 |
18Monitor | CVE-2015-5076No exploit | Multiple cross-site scripting (XSS) vulnerabilities in X2Engine X2CRM before 5.0.9 allow remote attackers to inject arbitrary web script or x2engine · x2crm · CWE-79 | Medium4.3 | — | 1.9% | Sep 29, 2015 |
- CVE-2013-569236Monitor
Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary l
HighCVSS 8.5Proof of conceptEPSS 6%x2engine · x2crmSep 30, 2013
- CVE-2014-266436Monitor
Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/ProfileController.php in
HighCVSS 8.8No exploitEPSS 3%x2engine · x2crmOct 17, 2017
- CVE-2015-507432Monitor
Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM be
HighCVSS 7.5Proof of conceptEPSS 8%x2engine · x2crmSep 29, 2015
- CVE-2014-529731Monitor
The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote attackers to conduc
HighCVSS 7.5No exploitEPSS 3%x2engine · x2engineOct 9, 2014
- CVE-2015-507528Monitor
Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of adminis
MediumCVSS 6.8Proof of conceptEPSS 3%x2engine · x2crmSep 29, 2015
- CVE-2020-2108724Monitor
Cross Site Scripting (XSS) in X2Engine X2CRM v6.9 and older allows remote attackers to execute arbitrary code by injecting arbitrary web scr
MediumCVSS 6.1No exploitEPSS 1%x2engine · x2crmApr 14, 2021
- CVE-2021-2728824Monitor
Cross Site Scripting (XSS) in X2Engine X2CRM v7.1 allows remote attackers to obtain sensitive information by injecting arbitrary web script
MediumCVSS 6.1No exploitEPSS 1%x2engine · x2crmApr 14, 2021
- CVE-2022-4817822Monitor
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action fu
MediumCVSS 5.4Proof of conceptEPSS 2%x2engine · x2crmApr 14, 2023
- CVE-2022-4817722Monitor
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importMo
MediumCVSS 5.4Proof of conceptEPSS 2%x2engine · x2crmApr 14, 2023
- CVE-2014-529821Monitor
FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attackers to bypass the up
MediumCVSS 5.0No exploitEPSS 3%x2engine · x2engineOct 9, 2014
- CVE-2024-4812021Monitor
X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module.
MediumCVSS 5.4Proof of conceptEPSS 1%x2engine · x2crmOct 14, 2024
- CVE-2021-3385321Monitor
A Cross-Site Scripting (XSS) attack can cause arbitrary code (javascript) to run in a user’s browser while the browser is connected to a tru
MediumCVSS 5.4No exploitEPSS 1%x2engine · x2crmMar 16, 2022
- CVE-2020-2108819Monitor
Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary w
MediumCVSS 4.8No exploitEPSS 1%x2engine · x2crmApr 14, 2021
- CVE-2013-569318Monitor
Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via the
MediumCVSS 4.3Proof of conceptEPSS 3%x2engine · x2crmSep 30, 2013
- CVE-2015-507618Monitor
Multiple cross-site scripting (XSS) vulnerabilities in X2Engine X2CRM before 5.0.9 allow remote attackers to inject arbitrary web script or
MediumCVSS 4.3No exploitEPSS 2%x2engine · x2crmSep 29, 2015