Записи Pagekit
13 опубликованных записей вендора pagekit.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 15,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2022-38916Эксплойта нет | A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious filespagekit · pagekit · CWE-434 | Критическая9,8 | — | 17,9 % | 20 сент. 2022 г. |
39Наблюдать | CVE-2021-44135Эксплойта нет | pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.pagekit · pagekit · CWE-89 | Критическая9,8 | — | 1,5 % | 1 апр. 2022 г. |
39Наблюдать | CVE-2025-67164Эксплойта нет | An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arpagekit · pagekit · CWE-78 | Критическая9,9 | — | 0,5 % | 17 дек. 2025 г. |
39Наблюдать | CVE-2025-67165Эксплойта нет | An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.pagekit · pagekit · CWE-639 | Критическая9,8 | — | 0,5 % | 17 дек. 2025 г. |
35Наблюдать | CVE-2019-19013Эксплойта нет | A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.pagekit · pagekit · CWE-352 | Высокая8,8 | — | 0,8 % | 22 нояб. 2019 г. |
32Наблюдать | CVE-2017-5594Proof of concept | An issue was discovered in Pagekit CMS before 1.0.11.pagekit · pagekit · CWE-640 | Высокая7,5 | — | 7,0 % | 25 янв. 2017 г. |
31Наблюдать | CVE-2023-41005Эксплойта нет | An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in Upagekit · pagekit · CWE-94 | Высокая7,8 | — | 0,6 % | 28 авг. 2023 г. |
24Наблюдать | CVE-2018-14381Эксплойта нет | Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.pagekit · pagekit · CWE-601 | Средняя6,1 | — | 1,0 % | 18 июл. 2018 г. |
24Наблюдать | CVE-2022-36573Эксплойта нет | A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted papagekit · pagekit · CWE-79 | Средняя6,1 | — | 0,6 % | 28 авг. 2022 г. |
21Наблюдать | CVE-2019-16669Эксплойта нет | The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is epagekit · pagekit · CWE-203 | Средняя5,3 | — | 1,1 % | 21 сент. 2019 г. |
21Наблюдать | CVE-2021-32245Эксплойта нет | In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS.pagekit · pagekit · CWE-79 | Средняя5,4 | — | 0,5 % | 16 июн. 2021 г. |
20Наблюдать | CVE-2018-11564Proof of concept | Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.pagekit · pagekit · CWE-79 | Средняя4,8 | — | 3,2 % | 1 июн. 2018 г. |
18Наблюдать | CVE-2024-45967Эксплойта нет | Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.pagekit · pagekit · CWE-79 | Средняя4,7 | — | 0,4 % | 1 окт. 2024 г. |
- CVE-2022-3891644В плане
A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files
КритическаяCVSS 9,8Эксплойта нетEPSS 18 %pagekit · pagekit20 сент. 2022 г.
- CVE-2021-4413539Наблюдать
pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %pagekit · pagekit1 апр. 2022 г.
- CVE-2025-6716439Наблюдать
An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute ar
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %pagekit · pagekit17 дек. 2025 г.
- CVE-2025-6716539Наблюдать
An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %pagekit · pagekit17 дек. 2025 г.
- CVE-2019-1901335Наблюдать
A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %pagekit · pagekit22 нояб. 2019 г.
- CVE-2017-559432Наблюдать
An issue was discovered in Pagekit CMS before 1.0.11.
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %pagekit · pagekit25 янв. 2017 г.
- CVE-2023-4100531Наблюдать
An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in U
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %pagekit · pagekit28 авг. 2023 г.
- CVE-2018-1438124Наблюдать
Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %pagekit · pagekit18 июл. 2018 г.
- CVE-2022-3657324Наблюдать
A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted pa
СредняяCVSS 6,1Эксплойта нетEPSS 1 %pagekit · pagekit28 авг. 2022 г.
- CVE-2019-1666921Наблюдать
The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is e
СредняяCVSS 5,3Эксплойта нетEPSS 1 %pagekit · pagekit21 сент. 2019 г.
- CVE-2021-3224521Наблюдать
In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %pagekit · pagekit16 июн. 2021 г.
- CVE-2018-1156420Наблюдать
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.
СредняяCVSS 4,8Proof of conceptEPSS 3 %pagekit · pagekit1 июн. 2018 г.
- CVE-2024-4596718Наблюдать
Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.
СредняяCVSS 4,7Эксплойта нетEPSS 0 %pagekit · pagekit1 окт. 2024 г.