Перейти к содержимому
Noroxi

Записи x2engine

15 опубликованных записей вендора x2engine.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
3
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

15 записей
  • CVE-2013-5692
    36Наблюдать

    Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary l

    ВысокаяCVSS 8,5Proof of conceptEPSS 6 %

    x2engine · x2crm30 сент. 2013 г.

  • CVE-2014-2664
    36Наблюдать

    Unrestricted file upload vulnerability in the ProfileController::actionUploadPhoto method in protected/controllers/ProfileController.php in

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    x2engine · x2crm17 окт. 2017 г.

  • CVE-2015-5074
    32Наблюдать

    Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM be

    ВысокаяCVSS 7,5Proof of conceptEPSS 8 %

    x2engine · x2crm29 сент. 2015 г.

  • CVE-2014-5297
    31Наблюдать

    The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote attackers to conduc

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    x2engine · x2engine9 окт. 2014 г.

  • CVE-2015-5075
    28Наблюдать

    Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of adminis

    СредняяCVSS 6,8Proof of conceptEPSS 3 %

    x2engine · x2crm29 сент. 2015 г.

  • CVE-2020-21087
    24Наблюдать

    Cross Site Scripting (XSS) in X2Engine X2CRM v6.9 and older allows remote attackers to execute arbitrary code by injecting arbitrary web scr

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    x2engine · x2crm14 апр. 2021 г.

  • CVE-2021-27288
    24Наблюдать

    Cross Site Scripting (XSS) in X2Engine X2CRM v7.1 allows remote attackers to obtain sensitive information by injecting arbitrary web script

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    x2engine · x2crm14 апр. 2021 г.

  • CVE-2022-48178
    22Наблюдать

    X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action fu

    СредняяCVSS 5,4Proof of conceptEPSS 2 %

    x2engine · x2crm14 апр. 2023 г.

  • CVE-2022-48177
    22Наблюдать

    X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importMo

    СредняяCVSS 5,4Proof of conceptEPSS 2 %

    x2engine · x2crm14 апр. 2023 г.

  • CVE-2014-5298
    21Наблюдать

    FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attackers to bypass the up

    СредняяCVSS 5,0Эксплойта нетEPSS 3 %

    x2engine · x2engine9 окт. 2014 г.

  • CVE-2024-48120
    21Наблюдать

    X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module.

    СредняяCVSS 5,4Proof of conceptEPSS 1 %

    x2engine · x2crm14 окт. 2024 г.

  • CVE-2021-33853
    21Наблюдать

    A Cross-Site Scripting (XSS) attack can cause arbitrary code (javascript) to run in a user’s browser while the browser is connected to a tru

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    x2engine · x2crm16 мар. 2022 г.

  • CVE-2020-21088
    19Наблюдать

    Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary w

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    x2engine · x2crm14 апр. 2021 г.

  • CVE-2013-5693
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via the

    СредняяCVSS 4,3Proof of conceptEPSS 3 %

    x2engine · x2crm30 сент. 2013 г.

  • CVE-2015-5076
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in X2Engine X2CRM before 5.0.9 allow remote attackers to inject arbitrary web script or

    СредняяCVSS 4,3Эксплойта нетEPSS 2 %

    x2engine · x2crm29 сент. 2015 г.