fork-cms kayıtları
fork-cms üreticisine ait 25 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %68
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')16
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-502 Deserialization of Untrusted Data2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
25 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-15521İstismar yok | Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing aspoon-library · spoon library · CWE-502 | Kritik9,8 | — | %2,5 | 26 Ağu 2019 |
36İzleyin | CVE-2020-24036İstismar yok | PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malicfork-cms · fork cms · CWE-502 | Yüksek8,8 | — | %3,0 | 4 Mar 2021 |
35İzleyin | CVE-2021-28931İstismar yok | Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a cfork-cms · fork cms · CWE-434 | Yüksek8,8 | — | %1,2 | 7 Tem 2021 |
35İzleyin | CVE-2022-1064İstismar yok | SQL injection through marking blog comments on bulk as spam in forkcms/forkcmsfork-cms · fork cms · CWE-89 | Yüksek8,8 | — | %1,2 | 25 Mar 2022 |
35İzleyin | CVE-2020-23960İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attackers to perform unaufork-cms · fork cms · CWE-352 | Yüksek8,8 | — | %0,7 | 11 Oca 2021 |
35İzleyin | CVE-2020-23264İstismar yok | Cross-site request forgery (CSRF) in Fork-CMS before 5.8.2 allow remote attackers to hijack the authentication of logged administrators.fork-cms · fork cms · CWE-352 | Yüksek8,8 | — | %0,6 | 6 May 2021 |
31İzleyin | CVE-2015-1467Kavram kanıtı | Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to execute arbitrary SQL cofork-cms · fork cms · CWE-89 | Yüksek7,5 | — | %2,4 | 6 Şub 2015 |
30İzleyin | CVE-2022-0153İstismar yok | SQL Injection in forkcms/forkcmsfork-cms · fork cms · CWE-89 | Yüksek7,5 | — | %1,1 | 24 Mar 2022 |
24İzleyin | CVE-2014-9470İstismar yok | Cross-site scripting (XSS) vulnerability in the loadForm function in Frontend/Modules/Search/Actions/Index.php in Fork CMS before 3.8.4 allofork-cms · fork cms · CWE-79 | Orta6,1 | — | %1,4 | 8 Şub 2020 |
24İzleyin | CVE-2018-17595İstismar yok | In the 5.4.0 version of the Fork CMS software, HTML Injection and Stored XSS vulnerabilities were discovered via the /backend/ajax URI.fork-cms · fork cms · CWE-79 | Orta6,1 | — | %1,0 | 2 Eki 2018 |
24İzleyin | CVE-2020-23263İstismar yok | Persistent Cross-site scripting vulnerability on Fork CMS version 5.8.2 allows remote attackers to inject arbitrary Javascript code via the fork-cms · fork cms · CWE-79 | Orta6,1 | — | %0,8 | 6 May 2021 |
24İzleyin | CVE-2020-13633İstismar yok | Fork before 5.8.3 allows XSS via navigation_title or title.fork-cms · fork cms · CWE-79 | Orta6,1 | — | %0,7 | 27 May 2020 |
21İzleyin | CVE-2012-1207İstismar yok | Directory traversal vulnerability in frontend/core/engine/javascript.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allows rfork-cms · fork cms · CWE-22 | Orta5,0 | — | %1,9 | 24 Şub 2012 |
21İzleyin | CVE-2022-0145İstismar yok | Cross-site Scripting (XSS) - Stored in forkcms/forkcmsfork-cms · fork cms · CWE-79 | Orta5,4 | — | %0,7 | 24 Mar 2022 |
21İzleyin | CVE-2020-23049İstismar yok | Fork CMS Content Management System v5.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the `Displayname` field whfork-cms · fork cms · CWE-79 | Orta5,4 | — | %0,6 | 22 Eki 2021 |
21İzleyin | CVE-2018-20682İstismar yok | Fork CMS 5.0.6 allows stored XSS via the private/en/settings facebook_admin_ids parameter (aka "Admin ids" input in the Facebook section).fork-cms · fork cms · CWE-79 | Orta5,4 | — | %0,6 | 9 Oca 2019 |
21İzleyin | CVE-2018-5215İstismar yok | Fork CMS 5.0.7 has XSS in /private/en/pages/edit via the title parameter.fork-cms · fork cms · CWE-79 | Orta5,4 | — | %0,5 | 4 Oca 2018 |
19İzleyin | CVE-2022-35585İstismar yok | A stored cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "start_date" Parfork-cms · fork cms · CWE-79 | Orta4,8 | — | %0,8 | 12 Ağu 2022 |
19İzleyin | CVE-2022-35587İstismar yok | A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publish_on_date" Parametefork-cms · fork cms · CWE-79 | Orta4,8 | — | %0,8 | 12 Ağu 2022 |
19İzleyin | CVE-2022-35589İstismar yok | A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publish_on_time" Parametefork-cms · fork cms · CWE-79 | Orta4,8 | — | %0,8 | 12 Ağu 2022 |
19İzleyin | CVE-2022-35590İstismar yok | A cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "end_date" Parameterfork-cms · fork cms · CWE-79 | Orta4,8 | — | %0,7 | 12 Ağu 2022 |
18İzleyin | CVE-2012-1188Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML vfork-cms · fork cms · CWE-79 | Orta4,3 | — | %4,5 | 25 Eyl 2012 |
18İzleyin | CVE-2012-1208Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2fork-cms · fork cms · CWE-79 | Orta4,3 | — | %4,1 | 24 Şub 2012 |
17İzleyin | CVE-2012-1209İstismar yok | Cross-site scripting (XSS) vulnerability in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allows rfork-cms · fork cms · CWE-79 | Orta4,3 | — | %1,2 | 24 Şub 2012 |
17İzleyin | CVE-2012-5164İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML vfork-cms · fork cms · CWE-79 | Orta4,3 | — | %1,2 | 25 Eyl 2012 |
- CVE-2019-1552140Planlayın
Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a cookie containing a
KritikCVSS 9,8İstismar yokEPSS %2spoon-library · spoon library26 Ağu 2019
- CVE-2020-2403636İzleyin
PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an authenticated remote user to execute malic
YüksekCVSS 8,8İstismar yokEPSS %3fork-cms · fork cms4 Mar 2021
- CVE-2021-2893135İzleyin
Arbitrary file upload vulnerability in Fork CMS 5.9.2 allows attackers to create or replace arbitrary files in the /themes directory via a c
YüksekCVSS 8,8İstismar yokEPSS %1fork-cms · fork cms7 Tem 2021
- CVE-2022-106435İzleyin
SQL injection through marking blog comments on bulk as spam in forkcms/forkcms
YüksekCVSS 8,8İstismar yokEPSS %1fork-cms · fork cms25 Mar 2022
- CVE-2020-2396035İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attackers to perform unau
YüksekCVSS 8,8İstismar yokEPSS %1fork-cms · fork cms11 Oca 2021
- CVE-2020-2326435İzleyin
Cross-site request forgery (CSRF) in Fork-CMS before 5.8.2 allow remote attackers to hijack the authentication of logged administrators.
YüksekCVSS 8,8İstismar yokEPSS %1fork-cms · fork cms6 May 2021
- CVE-2015-146731İzleyin
Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to execute arbitrary SQL co
YüksekCVSS 7,5Kavram kanıtıEPSS %2fork-cms · fork cms6 Şub 2015
- CVE-2022-015330İzleyin
SQL Injection in forkcms/forkcms
YüksekCVSS 7,5İstismar yokEPSS %1fork-cms · fork cms24 Mar 2022
- CVE-2014-947024İzleyin
Cross-site scripting (XSS) vulnerability in the loadForm function in Frontend/Modules/Search/Actions/Index.php in Fork CMS before 3.8.4 allo
OrtaCVSS 6,1İstismar yokEPSS %1fork-cms · fork cms8 Şub 2020
- CVE-2018-1759524İzleyin
In the 5.4.0 version of the Fork CMS software, HTML Injection and Stored XSS vulnerabilities were discovered via the /backend/ajax URI.
OrtaCVSS 6,1İstismar yokEPSS %1fork-cms · fork cms2 Eki 2018
- CVE-2020-2326324İzleyin
Persistent Cross-site scripting vulnerability on Fork CMS version 5.8.2 allows remote attackers to inject arbitrary Javascript code via the
OrtaCVSS 6,1İstismar yokEPSS %1fork-cms · fork cms6 May 2021
- CVE-2020-1363324İzleyin
Fork before 5.8.3 allows XSS via navigation_title or title.
OrtaCVSS 6,1İstismar yokEPSS %1fork-cms · fork cms27 May 2020
- CVE-2012-120721İzleyin
Directory traversal vulnerability in frontend/core/engine/javascript.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allows r
OrtaCVSS 5,0İstismar yokEPSS %2fork-cms · fork cms24 Şub 2012
- CVE-2022-014521İzleyin
Cross-site Scripting (XSS) - Stored in forkcms/forkcms
OrtaCVSS 5,4İstismar yokEPSS %1fork-cms · fork cms24 Mar 2022
- CVE-2020-2304921İzleyin
Fork CMS Content Management System v5.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the `Displayname` field wh
OrtaCVSS 5,4İstismar yokEPSS %1fork-cms · fork cms22 Eki 2021
- CVE-2018-2068221İzleyin
Fork CMS 5.0.6 allows stored XSS via the private/en/settings facebook_admin_ids parameter (aka "Admin ids" input in the Facebook section).
OrtaCVSS 5,4İstismar yokEPSS %1fork-cms · fork cms9 Oca 2019
- CVE-2018-521521İzleyin
Fork CMS 5.0.7 has XSS in /private/en/pages/edit via the title parameter.
OrtaCVSS 5,4İstismar yokEPSS %1fork-cms · fork cms4 Oca 2018
- CVE-2022-3558519İzleyin
A stored cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "start_date" Par
OrtaCVSS 4,8İstismar yokEPSS %1fork-cms · fork cms12 Ağu 2022
- CVE-2022-3558719İzleyin
A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publish_on_date" Paramete
OrtaCVSS 4,8İstismar yokEPSS %1fork-cms · fork cms12 Ağu 2022
- CVE-2022-3558919İzleyin
A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publish_on_time" Paramete
OrtaCVSS 4,8İstismar yokEPSS %1fork-cms · fork cms12 Ağu 2022
- CVE-2022-3559019İzleyin
A cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "end_date" Parameter
OrtaCVSS 4,8İstismar yokEPSS %1fork-cms · fork cms12 Ağu 2022
- CVE-2012-118818İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML v
OrtaCVSS 4,3Kavram kanıtıEPSS %4fork-cms · fork cms25 Eyl 2012
- CVE-2012-120818İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2
OrtaCVSS 4,3Kavram kanıtıEPSS %4fork-cms · fork cms24 Şub 2012
- CVE-2012-120917İzleyin
Cross-site scripting (XSS) vulnerability in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allows r
OrtaCVSS 4,3İstismar yokEPSS %1fork-cms · fork cms24 Şub 2012
- CVE-2012-516417İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary web script or HTML v
OrtaCVSS 4,3İstismar yokEPSS %1fork-cms · fork cms25 Eyl 2012