Записи Cotonti
6 опубликованных записей вендора cotonti.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2013-4789Proof of concept | SQL injection vulnerability in modules/rss/rss.php in Cotonti before 0.9.14 allows remote attackers to execute arbitrary SQL commands via thcotonti · cotonti siena · CWE-89 | Высокая7,5 | — | 2,6 % | 9 авг. 2013 г. |
21Наблюдать | CVE-2024-24115Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated attackers to executecotonti · cotonti siena · CWE-79 | Средняя5,4 | — | 0,4 % | 8 февр. 2024 г. |
21Наблюдать | CVE-2025-44115Эксплойта нет | A vulnerability has been found in Cotonti Siena v0.9.25.cotonti · cotonti siena · CWE-79 | Средняя5,4 | — | 0,3 % | 2 июн. 2025 г. |
20Наблюдать | CVE-2021-47808Эксплойта нет | Cotonti Siena 0.9.19 - 'maintitle' Stored Cross-Site Scriptingcotonti · cotonti siena · CWE-79 | Средняя5,1 | — | 0,3 % | 15 янв. 2026 г. |
19Наблюдать | CVE-2022-39839Эксплойта нет | Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a forum post.cotonti · cotonti siena · CWE-79 | Средняя4,8 | — | 0,5 % | 5 сент. 2022 г. |
19Наблюдать | CVE-2022-39840Эксплойта нет | Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a direct message (DM).cotonti · cotonti siena · CWE-79 | Средняя4,8 | — | 0,5 % | 5 сент. 2022 г. |
- CVE-2013-478931Наблюдать
SQL injection vulnerability in modules/rss/rss.php in Cotonti before 0.9.14 allows remote attackers to execute arbitrary SQL commands via th
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %cotonti · cotonti siena9 авг. 2013 г.
- CVE-2024-2411521Наблюдать
A stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated attackers to execute
СредняяCVSS 5,4Эксплойта нетEPSS 0 %cotonti · cotonti siena8 февр. 2024 г.
- CVE-2025-4411521Наблюдать
A vulnerability has been found in Cotonti Siena v0.9.25.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %cotonti · cotonti siena2 июн. 2025 г.
- CVE-2021-4780820Наблюдать
Cotonti Siena 0.9.19 - 'maintitle' Stored Cross-Site Scripting
СредняяCVSS 5,1Эксплойта нетEPSS 0 %cotonti · cotonti siena15 янв. 2026 г.
- CVE-2022-3983919Наблюдать
Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a forum post.
СредняяCVSS 4,8Эксплойта нетEPSS 0 %cotonti · cotonti siena5 сент. 2022 г.
- CVE-2022-3984019Наблюдать
Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a direct message (DM).
СредняяCVSS 4,8Эксплойта нетEPSS 0 %cotonti · cotonti siena5 сент. 2022 г.