codelyfe kayıtları
codelyfe üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-24 Path Traversal: '../filedir'2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-287 Improper Authentication1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2023-6901İstismar yok | codelyfe Stupid Simple CMS HTTP POST Request handle-command.php os command injectioncodelyfe · stupid simple cms · CWE-78 | Kritik9,8 | — | %2,9 | 17 Ara 2023 |
39İzleyin | CVE-2023-6902İstismar yok | codelyfe Stupid Simple CMS upload.php unrestricted uploadcodelyfe · stupid simple cms · CWE-434 | Kritik9,8 | — | %1,0 | 17 Ara 2023 |
36İzleyin | CVE-2023-6907İstismar yok | codelyfe Stupid Simple CMS Deletion Interface delete.php improper authenticationcodelyfe · stupid simple cms · CWE-287 | Kritik9,1 | — | %1,2 | 18 Ara 2023 |
35İzleyin | CVE-2024-27689İstismar yok | Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via /update-article.php.codelyfe · stupid simple cms · CWE-352 | Yüksek8,8 | — | %0,3 | 1 Mar 2024 |
35İzleyin | CVE-2024-22715İstismar yok | Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php.codelyfe · stupid simple cms · CWE-352 | Yüksek8,8 | — | %0,3 | 17 Oca 2024 |
26İzleyin | CVE-2023-7040İstismar yok | codelyfe Stupid Simple CMS rename.php path traversalcodelyfe · stupid simple cms · CWE-24 | Orta6,5 | — | %0,8 | 21 Ara 2023 |
25İzleyin | CVE-2024-27559İstismar yok | Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.phpcodelyfe · stupid simple cms · CWE-352 | Orta6,3 | — | %0,2 | 1 Mar 2024 |
24İzleyin | CVE-2024-27558İstismar yok | Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings.codelyfe · stupid simple cms · CWE-79 | Orta6,1 | — | %0,4 | 1 Mar 2024 |
24İzleyin | CVE-2024-22714İstismar yok | Stupid Simple CMS <=1.2.4 is vulnerable to Cross Site Scripting (XSS) in the editing section of the article content.codelyfe · stupid simple cms · CWE-79 | Orta6,1 | — | %0,4 | 17 Oca 2024 |
23İzleyin | CVE-2024-3202İstismar yok | codelyfe Stupid Simple CMS Login Page excessive authenticationcodelyfe · stupid simple cms · CWE-307 | Orta5,9 | — | %1,2 | 2 Nis 2024 |
21İzleyin | CVE-2023-7041İstismar yok | codelyfe Stupid Simple CMS rename.php path traversalcodelyfe · stupid simple cms · CWE-24 | Orta5,4 | — | %0,9 | 21 Ara 2023 |
- CVE-2023-690140Planlayın
codelyfe Stupid Simple CMS HTTP POST Request handle-command.php os command injection
KritikCVSS 9,8İstismar yokEPSS %3codelyfe · stupid simple cms17 Ara 2023
- CVE-2023-690239İzleyin
codelyfe Stupid Simple CMS upload.php unrestricted upload
KritikCVSS 9,8İstismar yokEPSS %1codelyfe · stupid simple cms17 Ara 2023
- CVE-2023-690736İzleyin
codelyfe Stupid Simple CMS Deletion Interface delete.php improper authentication
KritikCVSS 9,1İstismar yokEPSS %1codelyfe · stupid simple cms18 Ara 2023
- CVE-2024-2768935İzleyin
Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via /update-article.php.
YüksekCVSS 8,8İstismar yokEPSS %0codelyfe · stupid simple cms1 Mar 2024
- CVE-2024-2271535İzleyin
Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php.
YüksekCVSS 8,8İstismar yokEPSS %0codelyfe · stupid simple cms17 Oca 2024
- CVE-2023-704026İzleyin
codelyfe Stupid Simple CMS rename.php path traversal
OrtaCVSS 6,5İstismar yokEPSS %1codelyfe · stupid simple cms21 Ara 2023
- CVE-2024-2755925İzleyin
Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.php
OrtaCVSS 6,3İstismar yokEPSS %0codelyfe · stupid simple cms1 Mar 2024
- CVE-2024-2755824İzleyin
Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings.
OrtaCVSS 6,1İstismar yokEPSS %0codelyfe · stupid simple cms1 Mar 2024
- CVE-2024-2271424İzleyin
Stupid Simple CMS <=1.2.4 is vulnerable to Cross Site Scripting (XSS) in the editing section of the article content.
OrtaCVSS 6,1İstismar yokEPSS %0codelyfe · stupid simple cms17 Oca 2024
- CVE-2024-320223İzleyin
codelyfe Stupid Simple CMS Login Page excessive authentication
OrtaCVSS 5,9İstismar yokEPSS %1codelyfe · stupid simple cms2 Nis 2024
- CVE-2023-704121İzleyin
codelyfe Stupid Simple CMS rename.php path traversal
OrtaCVSS 5,4İstismar yokEPSS %1codelyfe · stupid simple cms21 Ara 2023